diff --git a/README.md b/README.md index 178362c..18aff64 100644 --- a/README.md +++ b/README.md @@ -130,12 +130,33 @@ Add these tags to your website's `
`: Now you can sign in to IndieAuth-compatible sites using `https://your-domain.com/` as your identity. +### Using as an OpenID Connect (OIDC) Provider + +Indiko also supports OpenID Connect (OIDC) for modern authentication flows: + +**Discovery endpoint:** +``` +https://your-indiko-domain.com/.well-known/openid-configuration +``` + +**Key features:** +- Authorization Code Flow with PKCE +- ID Token with RS256 signing +- JWKS endpoint for token verification +- Support for `openid`, `profile`, and `email` scopes +- Userinfo endpoint for retrieving user claims + +Test your OIDC setup using the [OIDC Debugger](https://oidcdebugger.com/). + ## API Reference -### OAuth 2.0 Endpoints +### OAuth 2.0 / OpenID Connect Endpoints -- `GET /auth/authorize` - Authorization endpoint -- `POST /auth/token` - Token exchange endpoint +- `GET /auth/authorize` - Authorization endpoint (OAuth 2.0 / OIDC) +- `POST /auth/token` - Token exchange endpoint (returns access token and ID token for OIDC) +- `GET /userinfo` - OIDC userinfo endpoint (returns user claims) +- `GET /.well-known/openid-configuration` - OIDC discovery document +- `GET /jwks` - JSON Web Key Set for ID token verification - `POST /auth/logout` - Session logout ### User Profile diff --git a/src/html/docs.html b/src/html/docs.html index 14a7c0e..4dedf84 100644 --- a/src/html/docs.html +++ b/src/html/docs.html @@ -577,6 +577,7 @@+ Indiko supports OpenID Connect (OIDC) for modern authentication flows, enabling "Sign in with Indiko" for any OIDC-compatible application. +
+ +| Endpoint | +Description | +
|---|---|
/.well-known/openid-configuration |
+ OIDC discovery document | +
/jwks |
+ JSON Web Key Set for ID token verification | +
/auth/authorize |
+ Authorization endpoint (same as OAuth 2.0) | +
/auth/token |
+ Token endpoint (returns ID token when openid scope requested) |
+
/userinfo |
+ OIDC userinfo endpoint | +
openid, profile, and email scopes
+ When the openid scope is requested, the token endpoint returns an ID token (JWT) containing:
+
iss - Issuer (Indiko server URL)sub - Subject (user identifier)aud - Audience (client ID)exp - Expiration timeiat - Issued at timeauth_time - Authentication timenonce - Nonce (if provided in authorization request)name, email, picture, website - User claims (based on granted scopes)openidprofileopenid scope is only relevant for OIDC flows and enables ID token issuance.