Support from the community to continue maintaining and improving this module is welcome. If you find the module useful, please consider supporting the project by becoming a sponsor.
| Name | Description |
|---|---|
| authorizationCodeGrant | Processes an authorization response and performs the Authorization Code Grant. |
| buildAuthorizationUrl | Builds an authorization request URL. |
| ClientMetadata | Client metadata that affects openid-client behavior. |
| discovery | Discovers authorization server metadata and creates a client configuration. |
| ServerMetadata | Metadata describing an OAuth 2.0 authorization server. |
| Name | Description |
|---|---|
| Configuration | Represents an authorization server and its client configuration. |
| discovery | Discovers authorization server metadata and creates a client configuration. |
| Function | Description |
|---|---|
| authorizationCodeGrant | Processes an authorization response and performs the Authorization Code Grant. |
| clientCredentialsGrant | Performs an OAuth 2.0 Client Credentials Grant. |
| genericGrantRequest | Performs an arbitrary OAuth grant request. |
| initiateBackchannelAuthentication | Initiates a Client-Initiated Backchannel Authentication request. |
| initiateDeviceAuthorization | Initiates an OAuth 2.0 Device Authorization Grant. |
| pollBackchannelAuthenticationGrant | Polls until a Client-Initiated Backchannel Authentication Grant completes. |
| pollDeviceAuthorizationGrant | Polls until an OAuth 2.0 Device Authorization Grant completes. |
| refreshTokenGrant | Performs an OAuth 2.0 Refresh Token Grant. |
| Function | Description |
|---|---|
| By default the module only allows interactions with HTTPS endpoints. This removes that restriction. | |
| dynamicClientRegistration | Discovers an authorization server and dynamically registers a client. |
| enableDecryptingResponses | Enables processing of encrypted authorization server responses. |
| enableDetachedSignatureResponseChecks | Enables FAPI 1.0 Advanced detached-signature response validation. |
| enableNonRepudiationChecks | Enables JWS signature validation for processed JWT responses. |
| getJwksCache | Exports the JSON Web Key Set cache used for signature validation. |
| setJwksCache | Imports an externally managed JSON Web Key Set cache. |
| useCodeIdTokenResponseType | Configures the client to use the OpenID Connect Hybrid Flow. |
| useIdTokenResponseType | Configures the client to use the OpenID Connect Implicit Flow. |
| useJwtResponseMode | Configures the client to use JWT Secured Authorization Response Mode (JARM). |
| Function | Description |
|---|---|
| ClientSecretBasic | Creates a client_secret_basic client authentication method. |
| ClientSecretJwt | Creates a client_secret_jwt client authentication method. |
| ClientSecretPost | Creates a client_secret_post client authentication method. |
| None | Creates a none client authentication method. |
| PrivateKeyJwt | Creates a private_key_jwt client authentication method. |
| TlsClientAuth | Creates a tls_client_auth client authentication method. |
| Class | Description |
|---|---|
| AuthorizationResponseError | Thrown when an OAuth 2.0 Authorization Error Response is encountered. |
| ClientError | An error raised by openid-client. |
| ResponseBodyError | Thrown when a server returns an OAuth-style error in a JSON response body. |
| WWWAuthenticateChallengeError | Thrown when a server response contains one or more parseable WWW-Authenticate challenges. |
| Function | Description |
|---|---|
| buildAuthorizationUrl | Builds an authorization request URL. |
| buildAuthorizationUrlWithJAR | Builds an authorization request URL using a JWT Secured Authorization Request (JAR). |
| buildAuthorizationUrlWithPAR | Builds an authorization request URL using Pushed Authorization Requests (PAR). |
| calculatePKCECodeChallenge | Calculates an S256 PKCE code_challenge from a code_verifier. |
| randomNonce | Generates a random OpenID Connect nonce value. |
| randomState | Generates a random OAuth 2.0 state value. |
| Function | Description |
|---|---|
| getDPoPHandle | Creates a DPoP handle for sender-constrained token requests. |
| randomDPoPKeyPair | Generates an asymmetric key pair for signing DPoP proofs. |
| Function | Description |
|---|---|
| dynamicClientRegistration | Discovers an authorization server and dynamically registers a client. |
| Function | Description |
|---|---|
| authorizationCodeGrant | Processes an authorization response and performs the Authorization Code Grant. |
| buildEndSessionUrl | Builds an RP-Initiated Logout URL. |
| discovery | Discovers authorization server metadata and creates a client configuration. |
| fetchUserInfo | Fetches and parses OpenID Connect UserInfo claims. |
| implicitAuthentication | Validates an OpenID Connect Implicit Flow response. |
| Function | Description |
|---|---|
| authorizationCodeGrant | Processes an authorization response and performs the Authorization Code Grant. |
| calculatePKCECodeChallenge | Calculates an S256 PKCE code_challenge from a code_verifier. |
| randomPKCECodeVerifier | Generates a random PKCE code_verifier value. |
| Function | Description |
|---|---|
| fetchProtectedResource | Fetches an arbitrary OAuth 2.0 protected resource. |
| fetchUserInfo | Fetches and parses OpenID Connect UserInfo claims. |
| Function | Description |
|---|---|
| tokenIntrospection | Retrieves the status and metadata of an OAuth 2.0 token. |
| tokenRevocation | Requests revocation of an OAuth 2.0 token. |
| Interface | Description |
|---|---|
| AuthorizationCodeGrantChecks | Expected values and validation checks for an Authorization Code Grant response. |
| AuthorizationCodeGrantOptions | Options for performing an Authorization Code Grant. |
| AuthorizationDetails | An entry in an OAuth 2.0 Rich Authorization Requests authorization_details array. |
| BackchannelAuthenticationGrantPollOptions | Options for polling a Client-Initiated Backchannel Authentication Grant. |
| BackchannelAuthenticationResponse | A parsed successful Client-Initiated Backchannel Authentication response. |
| ConfigurationMethods | Methods exposed by a Configuration instance. |
| ConfigurationProperties | Configurable properties exposed by a Configuration instance. |
| ConfirmationClaims | Proof-of-possession confirmation (cnf) claims associated with a token. |
| CryptoKeyPair | An asymmetric public and private CryptoKey pair. |
| CustomFetchOptions | Options passed to a custom HTTP request implementation. |
| DecryptionKey | An asymmetric private key and optional JOSE metadata used to decrypt responses. |
| DeviceAuthorizationGrantPollOptions | Options for polling an OAuth 2.0 Device Authorization Grant. |
| DeviceAuthorizationResponse | A parsed successful OAuth 2.0 Device Authorization Response. |
| DiscoveryRequestOptions | Options for authorization server metadata discovery. |
| DPoPHandle | A DPoP proof-generation and nonce-management handle returned by getDPoPHandle. |
| DPoPOptions | Options for making DPoP-bound requests. |
| DynamicClientRegistrationRequestOptions | Options for Dynamic Client Registration requests. |
| ExportedJWKSCache | A JSON Web Key Set cache value suitable for external persistence. |
| GenerateKeyPairOptions | Options for generating an asymmetric signing key pair. |
| IDToken | Claims from a validated OpenID Connect ID Token. |
| ImplicitAuthenticationResponseChecks | Expected values and validation checks for an OpenID Connect Implicit Flow response. |
| IntrospectionResponse | A parsed successful OAuth 2.0 Token Introspection response. |
| JWKS | A JSON Web Key Set. |
| ModifyAssertionFunction | A callback that mutates a JWT assertion header and claims immediately before signing. |
| ModifyAssertionOptions | Options for customizing a JWT assertion immediately before signing. |
| MTLSEndpointAliases | Authorization server endpoint aliases used for mutual TLS. |
| PrivateKey | An asymmetric private key with an optional JWK Key ID for JOSE headers. |
| ServerMetadataHelpers | Helpers for querying authorization server capabilities. |
| TokenEndpointResponse | A parsed successful OAuth 2.0 token endpoint response. |
| TokenEndpointResponseHelpers | Helpers attached to a parsed TokenEndpointResponse. |
| UserInfoAddress | The structured address claim in an OpenID Connect UserInfo response. |
| UserInfoResponse | Claims from a parsed OpenID Connect UserInfo response. |
| WWWAuthenticateChallenge | A parsed WWW-Authenticate challenge. |
| WWWAuthenticateChallengeParameters | Known and extension authentication parameters from a WWW-Authenticate challenge. |
| Type Alias | Description |
|---|---|
| ClientAuth | A function that applies client authentication to an authorization server request. |
| CryptoKey | A Web Cryptography key as declared by the host runtime. |
| CustomFetch | A Fetch API-compatible function used for outbound HTTP requests. |
| FetchBody | A request body supported by openid-client's Fetch API integration. |
| JsonArray | A JSON array. |
| JsonObject | A JSON object. |
| JsonPrimitive | A JSON primitive value. |
| JsonValue | Any JSON-compatible value. |
| JWK | A JSON Web Key with standard JOSE and supported extension parameters. |
| JWSAlgorithm | A supported JWS alg identifier for digital signature validation. |
| OmitSymbolProperties | Removes symbol-keyed properties from a type. |
| Variable | Description |
|---|---|
| clockSkew | Adjusts the current time used by protocol validations. |
| clockTolerance | Sets the allowed clock tolerance for JWT timestamp claim validation. |
| customFetch | Overrides the Fetch API implementation used for outbound HTTP requests. |
| modifyAssertion | Provides a hook for mutating JWT headers and claims immediately before signing. |
Skips authorization response state validation. |
|
Skips UserInfo sub claim validation. |