I guess I’m not understanding what your idea of a federated login looks like from your server perspective. I think that might be the fundamental problem as that idea is different for different people.
What I would envision a federated login looks like in the case of AP:
I are directed to a post on your forum. I don’t have a login to your forum and my home server has not subscribed to that forum from your server yet. I login at your server which redirects to my home instance, subscribes to the given forum and pulls in the post in question, automatically.
That seems like some extra steps now that I actually give the mechanics a thought and I think this can be resolved by an extra button on a post that does the above.
The fact that you said “my router doesn’t appear on file explorer” tells us everything we need to know about your skill level. You don’t know the first thing about “protecting this open port” and you aren’t qualified to assess the security risks of what you are trying to do.