From 745292c05d536809eedbbcc2d77bc6225e558043 Mon Sep 17 00:00:00 2001 From: Kieran Klukas Date: Sun, 11 Jan 2026 14:34:54 -0500 Subject: [PATCH] docs: add oidc --- README.md | 27 ++++++++++++++-- src/html/docs.html | 77 +++++++++++++++++++++++++++++++++++++++++++++- 2 files changed, 100 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 178362c..18aff64 100644 --- a/README.md +++ b/README.md @@ -130,12 +130,33 @@ Add these tags to your website's ``: Now you can sign in to IndieAuth-compatible sites using `https://your-domain.com/` as your identity. +### Using as an OpenID Connect (OIDC) Provider + +Indiko also supports OpenID Connect (OIDC) for modern authentication flows: + +**Discovery endpoint:** +``` +https://your-indiko-domain.com/.well-known/openid-configuration +``` + +**Key features:** +- Authorization Code Flow with PKCE +- ID Token with RS256 signing +- JWKS endpoint for token verification +- Support for `openid`, `profile`, and `email` scopes +- Userinfo endpoint for retrieving user claims + +Test your OIDC setup using the [OIDC Debugger](https://oidcdebugger.com/). + ## API Reference -### OAuth 2.0 Endpoints +### OAuth 2.0 / OpenID Connect Endpoints -- `GET /auth/authorize` - Authorization endpoint -- `POST /auth/token` - Token exchange endpoint +- `GET /auth/authorize` - Authorization endpoint (OAuth 2.0 / OIDC) +- `POST /auth/token` - Token exchange endpoint (returns access token and ID token for OIDC) +- `GET /userinfo` - OIDC userinfo endpoint (returns user claims) +- `GET /.well-known/openid-configuration` - OIDC discovery document +- `GET /jwks` - JSON Web Key Set for ID token verification - `POST /auth/logout` - Session logout ### User Profile diff --git a/src/html/docs.html b/src/html/docs.html index 14a7c0e..4dedf84 100644 --- a/src/html/docs.html +++ b/src/html/docs.html @@ -577,6 +577,7 @@

table of contents