Scene Image

Token Exchange

Guess I'll just have to trust the token exchange!

Puzzle Logic Game
In this text-based game, you play as a PyPI package maintainer who must navigate a complex system of token exchange using OpenID Connect. With each new package you publish, you must correctly configure PyPI to trust your identity token provided by a given OpenID Connect Identity Provider (IdP) and request new API tokens. But be careful! One wrong move and you could compromise security and lose access to publishing. Can you master the art of trusted publishing?