Skip to content

Reference

Glossary

The terms of these docs, in the contract's sense.

Access token
Authorizes calls to the app’s API. Lives 5 minutes; aud is the app’s client_id; carries no name or email.
aud (audience)
A token’s destination. In an IdP access token, the client_id of the requesting app. An API refuses any other aud.
BFF (backend for frontend)
The app’s server does the login and keeps the tokens; the browser gets only a session cookie. The recommended shape.
Claim
A field inside a token, such as sub or email. The IdP issues a closed set: Claims.
Confidential client
An app with a server; holds a secret and authenticates at the token endpoint. Uses PKCE as well.
Derived session
The app’s session, valid only while the central session is. Confirmed at every refresh.
Descriptor
The file clients/<clientId>.json that registers an app at the IdP. Enters by reviewed pull request.
Discovery
The document at <issuer>/.well-known/openid-configuration: endpoints and the JWKS location. Read at boot.
end_session_endpoint
The IdP’s logout endpoint. The app redirects the person there, with id_token_hint, to end the central session.
Fail closed
On error or unavailability, deny access. A failed refresh ends the local session, never extends it.
ID token
Identifies who signed in: sub, name, email. Not an API credential.
Invitation
Access the app records for an email before the person’s first login. Binds once to (iss, sub) at sign-in with that email verified.
iss (issuer)
Who issued the token. The IdP’s issuer is permanent.
JWKS
The IdP’s set of public keys for signature verification. Changes with key rotation.
nonce
A random value sent in the login request and returned inside the ID token. Binds the token to the request.
PKCE
Proof Key for Code Exchange: the SHA-256 hash of a single-use secret (S256) in the request, the secret at the code exchange. Mandatory for every client.
prompt=none
A login request with no screen: with a session at the IdP, it returns the person’s identity.
Public client
An app that runs only on a device or in a browser. No secret; PKCE only.
Refresh token
An opaque credential that trades an expired access token for a new one while the central session is valid. In a BFF, stays on the server.
Central session (SSO)
The person’s session at the IdP. Ends after 30 minutes idle or 10 hours, at logout, or when the account is blocked.
state
A random single-use value sent in the request and checked on the callback. Rejects answers the app did not ask for.
sub (subject)
The person’s stable identifier at this issuer. With iss, the person’s key in the app.
UserInfo
The endpoint that returns the identity claims to a holder of a valid access token.