Skip to content

OIDC Provider

In the console: Settings › Authentication › OIDC Provider

This server as a sign-in provider for apps: how long sign-ins last and which apps may register.

OAuth Settings

Key

Encryption key to use for OAuth.

Settings of their own: see Secret key. Name in the API: encryptionKey.

Max attempts

Number of failed login attempts before an authorization code is invalidated.

A number. Default: 3. Name in the API: authCodeMaxAttempts.

Token Expiration

User code

Expiration time of a user code issued by the device authentication flow.

A length of time. Default: 30m. Name in the API: userCodeExpiry.

Auth code

Expiration time of an authorization code issued by the authorization code flow.

A length of time. Default: 10m. Name in the API: authCodeExpiry.

Token

Expiration time of an OAuth access token.

A length of time. Default: 1h. Name in the API: accessTokenExpiry.

Refresh token

Expiration time of an OAuth refresh token.

A length of time. Default: 30d. Name in the API: refreshTokenExpiry.

Refresh token renew

Remaining time in a refresh token before a new one is issued to the client.

A length of time. Default: 4d. Name in the API: refreshTokenRenewal.

ID Token

Expiration time of an OpenID Connect ID token.

A length of time. Default: 15m. Name in the API: idTokenExpiry.

Dynamic Client Registration

Require client registration

Whether to require OAuth client_ids to be registered before they can be used.

On or off. Default: On. Name in the API: requireClientRegistration.

Allow anonymous registration

Whether to allow OAuth clients to register without authentication.

On or off. Default: Off. Name in the API: anonymousClientRegistration.

OpenID Connect

Signature algorithm

JWT signature algorithm to use for OpenID Connect.

One of: ECDSA using P-256 and SHA-256 (es256), ECDSA using P-384 and SHA-384 (es384), RSASSA-PSS using SHA-256 and MGF1 with SHA-256 (ps256), RSASSA-PSS using SHA-384 and MGF1 with SHA-384 (ps384), RSASSA-PSS using SHA-512 and MGF1 with SHA-512 (ps512), RSASSA-PKCS1-v1_5 using SHA-256 (rs256), RSASSA-PKCS1-v1_5 using SHA-384 (rs384), RSASSA-PKCS1-v1_5 using SHA-512 (rs512), HMAC using SHA-256 (hs256), HMAC using SHA-384 (hs384), HMAC using SHA-512 (hs512). Default: HMAC using SHA-256. Name in the API: signatureAlgorithm.

Signature Key

Contents of the private key PEM used to sign JWTs for OpenID Connect.

Settings of their own: see Secret text. Name in the API: signatureKey.