Developer guide

Build with Unified Identity

Connect your application to a shared identity with OAuth 2.0 and OpenID Connect. Start with an application, configure its client, and send your first sign-in request.

Create an application
Give your integration a name and choose its workspace.
Configure a client
Set the client type and exact callback URLs.
Connect an identity
Request the permissions your application needs.

01 · SETUP

Set up your application

Verify your account email, create a workspace, and wait for administrator or moderator approval. Then create your application from Applications.

Choose the right OAuth client

An application starts with a public Production client. Use a confidential client for a web application that can keep its secret on the server. Browser and native clients use a public client with PKCE.

Verify a production domain

Add a domain, publish its DNS TXT proof, verify ownership, and assign the verified hostname to your application. Production callbacks require HTTPS and an exact registered URL.

Keep local development separate

Create a Development client for exact loopback callbacks. Keep development and production redirect URLs on their respective clients.

02 · DISCOVERY

Find your provider configuration

Configure your OIDC client library with the issuer. Discovery provides the endpoints, signing keys, and supported capabilities.

OpenID Connect discovery
Configuration for the current identity server.
https://auth.dylojestem.com/.well-known/openid-configuration
Issuer
https://auth.dylojestem.com

03 · SIGN-IN

Use Authorization Code Flow

Use S256 PKCE, a random state, and a random nonce for every authorization request. Store those values and the code verifier in your client session.

Authorization request
Replace the placeholders with your registered client and callback.
const params = new URLSearchParams({
  client_id: "YOUR_CLIENT_ID",
  redirect_uri: "YOUR_REGISTERED_CALLBACK",
  response_type: "code",
  scope: "openid profile email",
  state: randomState,
  nonce: randomNonce,
  code_challenge: sha256Base64Url(codeVerifier),
  code_challenge_method: "S256",
});

const authorizationUrl =
  "https://auth.dylojestem.com/oauth/authorize?" + params;
  1. 1

    Redirect to authorize

    Send the user to the authorization URL. They sign in and review the requested permissions.

  2. 2

    Validate the callback

    Check that state matches your saved value, then exchange the one-use code with its original verifier and the exact callback URL.

  3. 3

    Validate the identity token

    Your OIDC library must verify the signature, issuer, audience, expiration, and nonce before establishing your application session.

04 · SCOPES

Request only the access you need

Start with openid. Add profile and email when your application uses that information.

ScopeAccess
openidIdentify the account and receive an ID token.
profileRead the account’s basic profile information.
emailRead the email address and verification status.
offline_accessKeep access using rotating refresh tokens.

Users can revoke access from Authorized applications. When they disconnect in your application, revoke its tokens and end the local application session. Workspace owners and administrators can also revoke a user’s current access or block future authorizations across that company’s applications. A block returns access_denied. Check token validity and end your own local session when provider access is revoked.

05 · REFERENCE

Provider endpoints

Resolve endpoints from discovery so your integration follows the provider’s configuration.

EndpointPurpose
/oauth/authorizeStart an authorization request
/oauth/tokenExchange codes and rotate refresh tokens
/oauth/userinfoRead approved account claims
/.well-known/jwks.jsonPublic keys for ID token validation
/oauth/revokeRevoke an access or refresh token
/oauth/introspectInspect tokens with an authorized confidential client
/oauth/logoutEnd the provider session

Keep client secrets on the server and use a maintained OIDC library for token validation.

Questions? Contact support