Build with Unified Identity
Connect your application to a shared identity with OAuth 2.0 and OpenID Connect. Start with an application, configure its client, and send your first sign-in request.
01 · SETUP
Set up your application
Verify your account email, create a workspace, and wait for administrator or moderator approval. Then create your application from Applications.
Choose the right OAuth client
An application starts with a public Production client. Use a confidential client for a web application that can keep its secret on the server. Browser and native clients use a public client with PKCE.
Verify a production domain
Add a domain, publish its DNS TXT proof, verify ownership, and assign the verified hostname to your application. Production callbacks require HTTPS and an exact registered URL.
Keep local development separate
Create a Development client for exact loopback callbacks. Keep development and production redirect URLs on their respective clients.
02 · DISCOVERY
Find your provider configuration
Configure your OIDC client library with the issuer. Discovery provides the endpoints, signing keys, and supported capabilities.
https://auth.dylojestem.com/.well-known/openid-configuration- Issuer
- https://auth.dylojestem.com
04 · SCOPES
Request only the access you need
Start with openid. Add profile and email when your application uses that information.
| Scope | Access |
|---|---|
| openid | Identify the account and receive an ID token. |
| profile | Read the account’s basic profile information. |
| Read the email address and verification status. | |
| offline_access | Keep access using rotating refresh tokens. |
Users can revoke access from Authorized applications. When they disconnect in your application, revoke its tokens and end the local application session. Workspace owners and administrators can also revoke a user’s current access or block future authorizations across that company’s applications. A block returns access_denied. Check token validity and end your own local session when provider access is revoked.
05 · REFERENCE
Provider endpoints
Resolve endpoints from discovery so your integration follows the provider’s configuration.
| Endpoint | Purpose |
|---|---|
| /oauth/authorize | Start an authorization request |
| /oauth/token | Exchange codes and rotate refresh tokens |
| /oauth/userinfo | Read approved account claims |
| /.well-known/jwks.json | Public keys for ID token validation |
| /oauth/revoke | Revoke an access or refresh token |
| /oauth/introspect | Inspect tokens with an authorized confidential client |
| /oauth/logout | End the provider session |