Skip to main content

OAuth / OIDC Endpoints

Every endpoint below is relative to your tenant's issuer, e.g. https://auth.yourtenant.com.

Discovery​

MethodPathDescription
GET/.well-known/openid-configurationStandard OIDC discovery document
GET/.well-known/jwks.jsonPublic signing keys, for verifying access/ID tokens yourself

Authorization Code flow​

MethodPathDescription
GET/authorizeStarts the sign-in flow. Params: client_id, redirect_uri, response_type=code, scope, state, optional code_challenge/code_challenge_method=S256 for PKCE
POST/tokenExchanges a grant for tokens — see grant types below
POST/revokeRevokes a refresh or access token
POST/introspectChecks whether a token is currently active, per RFC 7662
GET/userinfoReturns the signed-in user's claims, given a valid access token

Grant types accepted by /token​

grant_typeUse case
authorization_codeStandard web/mobile sign-in flow, following /authorize
client_credentialsMachine-to-machine — see Management API
refresh_tokenExchange a refresh token for a new access token without re-prompting the user
urn:ietf:params:oauth:grant-type:device_codeDevice Authorization Grant (RFC 8628) — see below

Device Authorization Grant​

For CLIs, TVs, and other input-constrained devices:

MethodPathDescription
POST/device_authorizationStarts the flow — returns a device_code, user_code, and a verification URL for the user to visit on a second device
POST/tokenPoll with grant_type=urn:ietf:params:oauth:grant-type:device_code until the user approves on the second device

Social / Enterprise connector endpoints​

MethodPathDescription
GET/auth/{providerName}/startRedirects to the named social/OAuth provider (e.g. /auth/google/start)
GET, POST/auth/{providerName}/callbackThe provider's redirect back to LoginLink
GET/auth/Saml/startStarts an SP-initiated SAML sign-in
POST/auth/Saml/acsSAML Assertion Consumer Service — where your IdP posts the signed assertion

See Authentication Methods for how to enable each of these per tenant.