1. Private link from Discord
The user will click “Verify account.” The bot will create a ten-minute session and return a link visible only to that person. The link token will have 256 bits of entropy and only its SHA‑256 digest will be stored.
Opening the page will not consume the link. An intentional form POST will start RSO, preventing automated link scanners from locking the user out.
2. Riot-hosted authorisation
The browser will go to auth.riotgames.com/authorize. Moon Poro will request only:
openid cpidopenid will identify the account and cpid will provide its League platform. We will not request offline_access, because the product will not refresh or store tokens.
3. Callback and identity
Riot will return to the exact registered callback. The service will consume and compare a one-time state, exchange the code server-to-server, read /riot/account/v1/accounts/me and obtain the platform from /userinfo.
The access token will exist only in memory for these requests. It will never be written to the database, a cookie, logs, or the Discord bot process.
4. Discord roles
The callback will atomically reserve the unique PUUID ↔ Discord link. The bot will retrieve the official Solo/Duo rank, apply the roles and send a private confirmation. Temporary Riot or Discord failures will use bounded retries.
For Riot Developer Relations
This page documents the planned public RSO flow for existing production application ID 524635. Reviewer access is shared privately in Developer Relations correspondence. The exact redirect URI is https://moonporo.pl/oauth2/callback.