Core endpoints
| Endpoint | Description |
|---|---|
/.well-known/openid-configuration |
OIDC discovery for the current issuer. |
/.well-known/oauth-protected-resource |
OAuth protected resource metadata for XID-hosted resource endpoints. |
/jwks |
Instance public signing keys with active and rotating kids. |
/authorize |
Authorization endpoint with PKCE, state, nonce, PAR, and Hosted Auth handoff. |
/par |
Pushed Authorization Requests with one-time request_uri values. |
/token |
Authorization code, refresh token, client credentials, device code, and token exchange. |
/userinfo |
Bearer or DPoP access token user claims. |
/end_session |
RP-initiated logout with registered post logout redirects. |
Protocol requirements
- PKCE uses S256. Plain PKCE is rejected.
- Redirect URI matching is exact. Wildcards are not accepted.
- Authorization codes are one-time use.
- Refresh tokens rotate on every use and replay revokes the token family.
- DPoP-bound clients must present a valid DPoP proof for token and resource calls. Authorization request
dpop_jktis bound to authorization code exchange.
Support levels
| Level | OAuth and OIDC features |
|---|---|
| Implemented | Authorization code, PKCE S256, refresh rotation, PAR, DPoP proof and dpop_jkt binding, dynamic client registration, ID tokens, userinfo, hybrid response types, signed JAR request objects, signed JARM responses, RAR resource_access authorization details, token exchange, mTLS client authentication, front-channel and back-channel logout, Device Flow, Session Management, CIBA, Browser-Based Apps profile gates, and FAPI 2.0 profile gates. |
| Minimal implementation | OpenID Federation exposes entity metadata and a registration boundary only. Trust-chain resolution, trust anchors, policy processing, and production interoperability are not implemented. |
| Planned | Shared Signals, CAEP, RISC, GNAP, UMA, HEART, OpenID4VP, and OpenID4VCI expose reserved routes that return explicit 501 errors. They are not protocol implementations. |
| Production evidence | Local implementation and conformance gates are not production certification. Downstream SaaS OIDC uses the generic OIDC baseline, but each SaaS integration still requires real external L4 evidence. |
| Deprecated or not supported | Implicit flow, password grant, plain PKCE, and wildcard redirects. |
Role boundaries
| XID role | Current public status |
|---|---|
| OIDC / OAuth identity provider for customer applications | Implemented in local and Worker routes with authorization code, PKCE S256, PAR, DPoP, JAR, JARM, RAR, discovery, JWKS, token, userinfo, introspection, and revocation coverage. |
| Upstream enterprise OIDC relying party | Provider-ready for enterprise connections. Production support requires a real IdP configuration and callback L4. |
| Social OAuth relying party | Provider-ready for GitHub, Google, Microsoft account, and Apple. See Social login for provider-specific boundaries. |
| Downstream SaaS OIDC identity provider | Generic OIDC baseline is available locally. SaaS-specific app templates and real SaaS L4 are still required before production support claims. |
Client types
| Client | Recommended flow |
|---|---|
| Web application | Authorization code with server side token exchange. |
| SPA | Authorization code with PKCE S256. |
| Native app | Authorization code with PKCE S256 and claimed redirects. |
| Machine to machine | Client credentials with scoped access. |
Guarded or minimal OAuth and OIDC extensions
| Level | Status |
|---|---|
| Assertion grants | JWT bearer and SAML bearer assertion grants are not enabled. Registration rejects assertion grant metadata until a trust root exists. |
| GNAP, UMA, HEART, OpenID4VP, OpenID4VCI | Only negative route and metadata stubs are exposed. Unsupported operations return explicit 501 unsupported_feature; no functional protocol support is claimed. |