@julian I now realise I was potentially confusing with my wording. I've largely got to the point of having the ability to get something with authorised fetch enabled, but the requirement to have so much else alongside the public key is making me a bit uneasy. The next paragraph was considering throwing this away and using the Mastodon API instead, although in addition to not being plain AP this would still be fiddly due to the client being on an embedded deviceThe idea of a proxy might actually be the least worst way to do it, I can limit the data it'll return to just the things I care about and not make users have to plug their device in to a PC to be able to authenticate to the API, I hadn't considered that