OIDC Provider¶
In the console: Settings › Authentication › OIDC Provider
This server as a sign-in provider for apps: how long sign-ins last and which apps may register.
OAuth Settings¶
Key¶
Encryption key to use for OAuth.
Settings of their own: see Secret key. Name in the API: encryptionKey.
Max attempts¶
Number of failed login attempts before an authorization code is invalidated.
A number. Default: 3. Name in the API: authCodeMaxAttempts.
Token Expiration¶
User code¶
Expiration time of a user code issued by the device authentication flow.
A length of time. Default: 30m. Name in the API: userCodeExpiry.
Auth code¶
Expiration time of an authorization code issued by the authorization code flow.
A length of time. Default: 10m. Name in the API: authCodeExpiry.
Token¶
Expiration time of an OAuth access token.
A length of time. Default: 1h. Name in the API: accessTokenExpiry.
Refresh token¶
Expiration time of an OAuth refresh token.
A length of time. Default: 30d. Name in the API: refreshTokenExpiry.
Refresh token renew¶
Remaining time in a refresh token before a new one is issued to the client.
A length of time. Default: 4d. Name in the API: refreshTokenRenewal.
ID Token¶
Expiration time of an OpenID Connect ID token.
A length of time. Default: 15m. Name in the API: idTokenExpiry.
Dynamic Client Registration¶
Require client registration¶
Whether to require OAuth client_ids to be registered before they can be used.
On or off. Default: On. Name in the API: requireClientRegistration.
Allow anonymous registration¶
Whether to allow OAuth clients to register without authentication.
On or off. Default: Off. Name in the API: anonymousClientRegistration.
OpenID Connect¶
Signature algorithm¶
JWT signature algorithm to use for OpenID Connect.
One of: ECDSA using P-256 and SHA-256 (es256), ECDSA using P-384 and SHA-384 (es384), RSASSA-PSS using SHA-256 and MGF1 with SHA-256 (ps256), RSASSA-PSS using SHA-384 and MGF1 with SHA-384 (ps384), RSASSA-PSS using SHA-512 and MGF1 with SHA-512 (ps512), RSASSA-PKCS1-v1_5 using SHA-256 (rs256), RSASSA-PKCS1-v1_5 using SHA-384 (rs384), RSASSA-PKCS1-v1_5 using SHA-512 (rs512), HMAC using SHA-256 (hs256), HMAC using SHA-384 (hs384), HMAC using SHA-512 (hs512). Default: HMAC using SHA-256. Name in the API: signatureAlgorithm.
Signature Key¶
Contents of the private key PEM used to sign JWTs for OpenID Connect.
Settings of their own: see Secret text. Name in the API: signatureKey.