This architectural proposal covers a same-device connection flow: the user taps Connect Spending in Zaprite, approves access in Lexe on the same phone, and returns to Zaprite with a usable connection. It builds on Lexe's proposed connection flow and keeps Lexe's existing credential model. The aim is to agree with Lexe on the architecture: the security mechanisms, trust assumptions, and responsibilities of each side. Once those choices are agreed, a separate protocol specification will define the exact message formats, cryptographic parameters, and validation rules that both implementations must follow.
| Challenge | Solutions |
|---|---|
| 1. Prove Zaprite approved the requestHow does Lexe know this exact connection request was approved by Zaprite? | Recommended solution: Zaprite's server signs |