documentation /api provider

OpenID Connect

API provider

Generic OpenID Connect (OIDC) authentication. Supports any OIDC-compliant identity provider (Okta, Azure AD, Auth0, etc.).

  • API category: OpenID Connect
  • Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow

Configuration parameters

Required

  • description : string; required
    Human-readable label for this OIDC provider (shown on the login button).
  • authorize_url : string; required
    OIDC authorization endpoint URL.
  • access_token_url : string; required
    OIDC token endpoint URL.
  • userinfo_url : string; required
    OIDC userinfo endpoint URL (used to fetch the user’s profile after sign-in).
  • client_id : string; required
    OIDC client ID registered with the provider.
  • client_secret : string; required
    OIDC client secret.

Optional

  • issuer : string; optional
    OIDC issuer URL (e.g. https://example.okta.com/oauth2/default). It tells callers where to authenticate. Set this, introspection_url and audience together, and only when this app accepts access tokens from the provider rather than just logging users in; setting some but not all of the three is an error.
  • introspection_url : string; optional
    RFC 7662 token introspection endpoint URL. Set this, issuer and audience together, and only when this app accepts access tokens from the provider.
  • audience : string; optional
    Resource identifier an inbound access token must carry in its aud claim, normally this app’s own URL. Register it as an API/resource in your identity provider. Set this, issuer and introspection_url together, and only when this app accepts access tokens from the provider.

What components can use this API

Concepts:

Ingredients: