I'm exploring a new idea called FediOTP (codename): an authentication system that uses #ActivityPub DMs to deliver one-time passwords, allowing any #fediverse account to authenticate with web services. Unlike current solutions that rely on specific APIs (#Mastodon, #Misskey), this would work with any ActivityPub-compatible server, increasing interoperability across the fediverse. Would love to hear your thoughts on potential challenges or use cases for this approach.
@hongminhee洪 民憙 (Hong Minhee) it's not a bad idea, but I think OIDC is still better. I have some notes here:
https://evanp.me/2024/04/22/cross-server-interactions-in-activitypub/

Cross-server Interactions in ActivityPub
So, Richard McManus asked me about how ActivityPub supports cross-server usage. As an example use case, let’s say a user with the account eric@social.example wants to comment on a photo by di…
evanp.me · Evan Prodromou's Blog
Link author: Evan Prodromou@evanprodromou@evanp.me
If you have a fediverse account, you can quote this note from your own instance. Search https://cosocial.ca/users/evan/statuses/114402183161479748 on your instance and quote it. (Note that quoting is not supported in Mastodon.)