Reference
Glossary
The terms of these docs, in the contract's sense.
- Access token
- Authorizes calls to the app’s API. Lives 5 minutes;
audis the app’sclient_id; carries no name or email. aud(audience)- A token’s destination. In an IdP access token, the
client_idof the requesting app. An API refuses any otheraud. - BFF (backend for frontend)
- The app’s server does the login and keeps the tokens; the browser gets only a session cookie. The recommended shape.
- Claim
- A field inside a token, such as
suboremail. The IdP issues a closed set: Claims. - Confidential client
- An app with a server; holds a secret and authenticates at the token endpoint. Uses PKCE as well.
- Derived session
- The app’s session, valid only while the central session is. Confirmed at every refresh.
- Descriptor
- The file
clients/<clientId>.jsonthat registers an app at the IdP. Enters by reviewed pull request. - Discovery
- The document at
<issuer>/.well-known/openid-configuration: endpoints and the JWKS location. Read at boot. end_session_endpoint- The IdP’s logout endpoint. The app redirects the person there, with
id_token_hint, to end the central session. - Fail closed
- On error or unavailability, deny access. A failed refresh ends the local session, never extends it.
- ID token
- Identifies who signed in:
sub, name, email. Not an API credential. - Invitation
- Access the app records for an email before the person’s first login. Binds once to
(iss, sub)at sign-in with that email verified. iss(issuer)- Who issued the token. The IdP’s issuer is permanent.
- JWKS
- The IdP’s set of public keys for signature verification. Changes with key rotation.
nonce- A random value sent in the login request and returned inside the ID token. Binds the token to the request.
- PKCE
- Proof Key for Code Exchange: the SHA-256 hash of a single-use secret (S256) in the request, the secret at the code exchange. Mandatory for every client.
prompt=none- A login request with no screen: with a session at the IdP, it returns the person’s identity.
- Public client
- An app that runs only on a device or in a browser. No secret; PKCE only.
- Refresh token
- An opaque credential that trades an expired access token for a new one while the central session is valid. In a BFF, stays on the server.
- Central session (SSO)
- The person’s session at the IdP. Ends after 30 minutes idle or 10 hours, at logout, or when the account is blocked.
state- A random single-use value sent in the request and checked on the callback. Rejects answers the app did not ask for.
sub(subject)- The person’s stable identifier at this issuer. With
iss, the person’s key in the app. - UserInfo
- The endpoint that returns the identity claims to a holder of a valid access token.