Portals
A brand store on Aeonis can have a back door. Through it a visitor can step into the brand's own world inside Aeonis, or be offered a link to a 3D web world that lives on another website. This page is the public rulebook and the list of open doors.
Open doors
No doors are open yet.
Two kinds of door
A world inside Aeonis. The brand's back door is a gate at the rear of its store. A visitor presses Act (E or Enter on a keyboard, the door button on a phone, Square on a controller) and steps into a small world with its own sky, light and gravity, chosen from a short fixed list: sky indoors, day, dusk, night or void; gravity Earth, Moon or none. The world is data (rooms, doors, plinths, signs) built by Aeonis code, so it loads no files from the brand. There is always an Exit that returns the visitor to the street.
A world on another website. A verified brand gives the https address of a 3D web world it owns or may link. After a check and a person's approval the store gets a side door. Using it shows a screen that says You are leaving Aeonis to the site's name, with Continue and Stay. Continue opens the site in a new tab.
Aeonis Passport: what travels, only if the visitor says so
By default nothing about the visitor is passed on. The new tab is opened with noopener and noreferrer, so the site does not even learn the visitor came from Aeonis. A door can ask for Aeonis Passport items. Then the leaving screen lists each item the door asked for, shows the exact value that would be sent, and has a tick box for each. Only ticked items are sent.
- Avatar: a public link to a standard glTF 2.0 humanoid file (the CC0 avatar described below) plus the visitor's two colours.
- Display name: the name the visitor typed for Passport. Only for visitors who say they are 18 or over.
- A code for this site: an opaque identifier that is different for every site and every device seed. It is not the visitor's email, an account number or anything that works on another site. Two sites cannot compare notes.
- Language and device type: for example
en-GBandphone,tabletordesktop. - Return link: the address of the store on Aeonis, so the world can offer a way back.
The visitor can choose Remember my choice for this site or Never share anything with this site, can see a list of what was shared with which site (You > Account), and can revoke everything at once there. Passport is off until the visitor turns it on and says how old they are. It is not available to people under 13 or who do not say, and the age is what the person says: Aeonis cannot check it. Passport settings are kept on the visitor's device. Aeonis keeps no list of who shared what with whom; it counts how many tokens were made per door and nothing else.
Safeguards: only approved doors can receive a Passport, and the items a door may ask for are part of what a person at Aeonis approves; a person at Aeonis can switch the Passport off for any one door at once; token making is rate-limited; a token made for one site is useless at another.
Passport token (for worlds that receive one)
The token is a JWT signed with Ed25519 (alg = EdDSA), valid for 5 minutes, and is placed in the address fragment, which browsers do not send to any server and do not put in a Referer: https://your-world.example/path#aeonis_passport=<token>. Read it in your page, then remove it from the address bar (history.replaceState).
Public keys: https://hub.aeonis.pro/.well-known/jwks.json (also /api/passport/jwks). The test site next.aeonis.pro has its own key and its own iss.
header {"alg":"EdDSA","typ":"JWT","kid":"<key id>"}
claims {"iss":"https://hub.aeonis.pro",
"aud":"your-world.example", // your host, exactly
"iat":1760000000,"exp":1760000300, // 5 minutes
"jti":"<random, unique>",
"sub":"aps_<opaque>", // only if the code was ticked; the same visitor gets a different one at every site
"passport":{"v":1,"items":["avatar","name","id","locale","return"], // exactly what was ticked
"name":"Alex", // if ticked
"avatar":{"glb":"https://hub.aeonis.pro/models/npc.glb","format":"glTF-2.0-humanoid","rig":"aeonis-ual-1","licence":"CC0-1.0",
"colors":{"body":"#3f7fbf","trim":"#59607a"}}, // if ticked
"locale":"en-GB","device":"phone", // if ticked
"return":"https://hub.aeonis.pro/?place=your-store-id"}} // if ticked
To verify: check the signature against the JWKS (only EdDSA), iss is the Aeonis address you expect, aud equals your host, exp has not passed, and (if you can) that you have not seen the jti before. With the jose library: jwtVerify(token, createRemoteJWKSet(new URL('https://hub.aeonis.pro/.well-known/jwks.json')), {issuer:'https://hub.aeonis.pro', audience:location.hostname, algorithms:['EdDSA']}). Treat everything inside as visitor-supplied text: show names as text, never as HTML. Do not log the token. Keep the code (sub) only as long as you need it, and say what you do with it in your own privacy notice.
Avatar format
glTF 2.0 binary (.glb), one skinned humanoid mesh, metres, Y up. The Aeonis avatar (/models/npc.glb) is the CC0 1.0 mannequin and animation set from Quaternius' Universal Animation Library: about 13,700 triangles, 665 KB, no textures, two materials (M_Main clothes, M_Joints trim, set by baseColorFactor), the KHR_mesh_quantization extension, a 65-bone skeleton and nine animation loops (idle, talk, walk, walkFormal, jog, interact, drive, sit, sitTalk). The colours in the token are the values to put on those two materials. Bone names, with the matching VRM 1.0 humanoid name where there is one:
root (no VRM bone: the origin) pelvis → hips spine_01 → spine spine_02 → chest spine_03 → upperChest neck_01 → neck Head → head clavicle_l/_r → leftShoulder/rightShoulder upperarm_l/_r → leftUpperArm/rightUpperArm lowerarm_l/_r → leftLowerArm/rightLowerArm hand_l/_r → leftHand/rightHand thigh_l/_r → leftUpperLeg/rightUpperLeg calf_l/_r → leftLowerLeg/rightLowerLeg foot_l/_r → leftFoot/rightFoot ball_l/_r → leftToes/rightToes (ball_leaf_l/_r: end points) thumb_01..03_l/_r → thumb Metacarpal, Proximal, Distal index/middle/ring/pinky_01..03_l/_r → Proximal, Intermediate, Distal (…_04_leaf_l/_r: end points)
Limits for an avatar file (for the files we serve, and for files we may accept from other standard sources later): at most 10 MB, 100,000 triangles, 4 materials, textures up to 2048 by 2048 pixels, up to 256 bones, a single skin. Other humanoid GLBs with these bone names or the VRM humanoid names can be mapped to the same rig; at present Aeonis serves only its own avatar and accepts no others.
Visitors can download their avatar from You > Account as a GLB with their two colours already set (the file also says so in its asset.extras). It is CC0: use it anywhere.
Return links: from your world back to Aeonis
If a door's Passport includes return, your world can send the visitor back with a token you sign yourself. Publish your public Ed25519 key as a JWK Set at https://your-world.example/.well-known/aeonis-partner-jwks.json (with a kid), and send the visitor to https://hub.aeonis.pro/#aeonis_return=<token>. Claims: iss your host exactly, aud the iss you received (the Aeonis address), iat and exp (at most 10 minutes), sub the code you received (optional; if present it must be the visitor's), and ret: {"note":"up to 80 plain characters"}. Aeonis checks the signature against your published key, that the door is approved and not switched off, and then lands the visitor in your store on Aeonis with the note shown as plain text. A return link can only lead to your own store.
Portal link spec
- Address:
https://only, a public host name (no IP address, nolocalhost, no internal names), no user name or password in it, standard port, up to 300 characters. - Not allowed: any other scheme (such as
fivem://or a game-launcher link), servers of closed games, chat invites, link shorteners, and addresses that download a file. - Name: 2 to 60 plain characters shown on the door and on the leaving screen.
- The page must answer with a normal web page (status 200 to 299,
text/html) within a few seconds, and must stay on the same site: an address that redirects to another site is not accepted. - One portal per store. Changing the address starts the check and approval again.
Proving control: the manifest
If the address is on the brand's verified domain (or below it), nothing more is needed. Otherwise show that you control it in either of two ways. Aeonis gives you a one-time token in the brand dashboard.
https://your-world.example/.well-known/aeonis-portal.json
{"v":1,"place":"your-store-id","token":"the-token-from-your-dashboard"}
or a DNS record: _aeonis.your-world.example as TXT with the value aeonis-portal=the-token-from-your-dashboard (the same idea as the record used to claim a store).
How to apply
- Claim your store and be approved as its contact (claim a place).
- Open the brand dashboard, go to External portal, and enter the address and the name.
- Show control (above) and run the check. It tests the address rules, the proof and that the page loads.
- A person at Aeonis looks at the page and approves it or says why not. You see the answer in the dashboard.
Rules and safety
- Only worlds the brand owns or has the right to link. No closed-game launchers or servers, no content that is illegal, deceptive, or aimed at collecting visitors' passwords or payment details.
- After approval Aeonis looks at the page about every half hour. A page that stops answering for three checks in a row is taken down until it is fixed; a page that starts redirecting to another site is taken down at once. Every take-down is recorded.
- Aeonis may suspend or remove any portal at any time.
- Aeonis does not run, host or vouch for the outside site. Once a visitor continues, that site's own rules apply.
Takedown and safety reports
If a door leads somewhere unsafe or you own a site that should not be linked, use the contact form and write "portal takedown" and the shop's name. A person reads it and acts on it.
Counts
For visitors who allowed counts, Aeonis counts per store and day how many opened the back door, how many reached the leaving screen and how many pressed Continue. Nothing links a count to a person. Brands see their own totals; the numbers are not published.
As an Amazon Associate we earn from qualifying purchases.