Battle.net OAuth · Armory sync

Your stable, have vs. missing.

Connect with Battle.net, pick a character, and we compare your Armory mounts against the full retail database — filtered by difficulty so you always know the next easiest win.

🔐 How login works (privacy-first)

  1. Authorization Code Flow + PKCE via /api/auth/login → Battle.net. Tokens stay server-side in Pages Functions; browser keeps only an httpOnly session cookie.
  2. Scopes: wow.profile (read your mounts). We never see your password.
  3. /api/collection?realm=&character= proxies the Armory collections/mounts endpoint so the Client Secret never ships to the browser.
  4. Demo mode uses local sample data — no network, no login.