Skip to content

Reference

Endpoints

The discovery fields an app uses; the contract, not discovery's full list, defines the client.

An app configures one address: the issuer. Every other endpoint comes from https://id.institutourupema.com.br/realms/urupema/.well-known/openid-configuration, read at boot.

FieldFor
issuermust equal the configured issuer; the iss of every token
authorization_endpointsign-in redirect (response_type=code, PKCE S256)
token_endpointcode exchange and refresh
userinfo_endpointname and email for a holder of only the access token (an API)
jwks_uripublic keys that sign tokens; follow rotation
end_session_endpointlogout, with id_token_hint and post_logout_redirect_uri

Excerpt, production values:

openid-configuration (excerpt)
{
"issuer": "https://id.institutourupema.com.br/realms/urupema",
"authorization_endpoint": "https://id.institutourupema.com.br/realms/urupema/protocol/openid-connect/auth",
"token_endpoint": "https://id.institutourupema.com.br/realms/urupema/protocol/openid-connect/token",
"userinfo_endpoint": "https://id.institutourupema.com.br/realms/urupema/protocol/openid-connect/userinfo",
"end_session_endpoint": "https://id.institutourupema.com.br/realms/urupema/protocol/openid-connect/logout",
"jwks_uri": "https://id.institutourupema.com.br/realms/urupema/protocol/openid-connect/certs",
"authorization_response_iss_parameter_supported": true
}

Discovery lists the engine’s capabilities for the whole realm: implicit flow, password grant, token exchange, scopes such as phone and roles, PKCE plain, claims such as given_name. None of that applies to a managed client. The contract applies:

Discovery advertisesYour client gets
grant_types_supported: authorization_code, implicit, password, client_credentials, token exchange…authorization_code and refresh_token
code_challenge_methods_supported: plain, S256S256 only
scopes_supported: openid, profile, email, phone, address, roles, offline_access…openid profile email
claims_supported: includes given_name, family_namethe claims in Claims