So first, great idea & thank you so much for doing this.
On the privacy leak front, having this one site manage all your non-SQRL supporting sites OAUTH grants does create a small deanonymization issue, assuming that is that you don't leak the SQRL public key as part of the grant object, in...