# App Authentication to Replace "WebTransceiver" Auth: Testing Open

**URL:** <https://community.allstarlink.org/t/app-authentication-to-replace-webtransceiver-auth-testing-open/25051>\
**Category:** AllStarLink\
**Created:** [October 6, 2026, 11:37pm UTC](https://community.allstarlink.org/t/app-authentication-to-replace-webtransceiver-auth-testing-open/25051 "2026-10-06T23:37:47Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![N8EI](https://community.allstarlink.org/user_avatar/community.allstarlink.org/n8ei/32/4254_2.png) [@N8EI](https://community.allstarlink.org/u/N8EI)\
**Post date:** [October 6, 2026, 11:37pm UTC](https://community.allstarlink.org/t/app-authentication-to-replace-webtransceiver-auth-testing-open/25051/1 "2026-10-06T23:37:47Z")

</div>

As announced at [https://community.allstarlink.org/t/request-for-comment-application-authentication/24979](https://community.allstarlink.org/t/request-for-comment-application-authentication/24979), the forthcoming _App Authentication_ is in development to replace the legacy "WebTransceiver" authentication mode. The standard ASL002 has moved into the _Accepted_ state and development is largely complete. _Please note this is **NOT** removing app-based communications it is ONLY changing how they authenticate._

App developers and node owners please take note of the following information.

### Standards Information

The complete implementation information can be found at [ASL002 Application Authentication](https://github.com/AllStarLink/Standards/blob/main/ASL002-App_Authentication.md)

### Development API is Available

The API is available for development testing at [https://api-dev.allstarlink.org](https://api-dev.allstarlink.org). The new API system supports OpenAPI documentation syntax and can be found at [https://api-dev.allstarlink.org/schema/#tag/appauth](https://api-dev.allstarlink.org/schema/#tag/appauth).

Additionally, test script to demonstrate the the AppAuth API can be retrieved from [https://api-dev.allstarlink.org/examples/appauth\_client.py](https://api-dev.allstarlink.org/examples/appauth_client.py).

Note that `api-dev.allstarlink.org` may be perioditically unworking or unavailable as the code is being tested. However we expect this to be up at least 90% of the time between now and go-live.

### Tentative Schedule

The following _ **TENTATIVE** _ deployment and implementation schedule is under review pending final QA testing of the system:

- **December 5, 2026:** AppAuth is considered deployed and begins the 366 day deprecation and removal schedule of the 'WebTransceiver auth' system.

- **June 3, 2027:** App logins using "WebTransceiver auth" will no longer be supported:

- **December 6, 2027:** Legacy and transitional methods described as RV2, RV3, and RV4 in ASL002 will be removed for node-based client verification. _ **Nodes that have not updated their `extensions.conf` will no longer be able to authenticate app clients.** _

### Remaining Tasks

The following remaining tasks are necessary to completed before the transition begins:

Complete QA testing of the API system and deploy to production  
 Complete packaging changes to update `extensions.conf` in ASL3 installations  
 Provide a script and/or directions for legacy ASL and HamVOIP users to update `extensions.conf`  
 Send a complete announcement to all users ~ 2 weeks prior to the "go live" date

Inability to complete the above by mid-November will push the timeline into January 2027.
