Generate authentication challenge
Public endpoint that generates a challenge for three-party JWT authentication.
Security Notes:
- Public endpoint, requires external rate limiting
- Nonce is single-use and expires based on JWT
exp_pohclaim - Device stores up to 50 nonces with FIFO eviction
Flow:
- Client calls this endpoint to get challenge
- Client presents challenge to auth server with user credentials
- Auth server issues JWT with nonce and expiration
- Client submits JWT to
/auth/loginendpoint
Response
Challenge generated successfully
sn
Device serial number (audience for JWT validation)
now_poh
Current power-on hours (for POH-based expiration)
nonce
128-bit random nonce (base64url, 22 chars) for replay protection
fw
Firmware version (semver)
Errors
500
Internal Server Error

