/** * Generate an ES256 JWK private key for FlockOff's OAuth confidential client. * * Usage: * node scripts/generate-key.mjs * * Copy the output into your .env file as OAUTH_PRIVATE_KEY. * Keep this key secret — it authenticates the app to Bluesky's authorization servers. */ import { webcrypto } from 'crypto' const keyPair = await webcrypto.subtle.generateKey( { name: 'ECDSA', namedCurve: 'P-256' }, true, ['sign', 'verify'] ) const jwk = await webcrypto.subtle.exportKey('jwk', keyPair.privateKey) // Add standard metadata fields — note: 'use' is omitted, 'key_ops' is sufficient jwk.kid = 'key1' jwk.alg = 'ES256' const json = JSON.stringify(jwk) console.log('─'.repeat(60)) console.log('FlockOff OAuth Private Key') console.log('─'.repeat(60)) console.log('') console.log('Add this line to your .env.local file:') console.log('') console.log(`OAUTH_PRIVATE_KEY='${json}'`) console.log('') console.log('─'.repeat(60)) console.log('Keep this key secret. Do not commit it to git.') console.log('─'.repeat(60))