Skip to content

Latest commit

 

History

History
192 lines (158 loc) · 14.3 KB

File metadata and controls

192 lines (158 loc) · 14.3 KB

openid-client API Reference

💗 Help the project

Support from the community to continue maintaining and improving this module is welcome. If you find the module useful, please consider supporting the project by becoming a sponsor.

You are probably looking for this

Name Description
authorizationCodeGrant Processes an authorization response and performs the Authorization Code Grant.
buildAuthorizationUrl Builds an authorization request URL.
ClientMetadata Client metadata that affects openid-client behavior.
discovery Discovers authorization server metadata and creates a client configuration.
ServerMetadata Metadata describing an OAuth 2.0 authorization server.

Configuration

Name Description
Configuration Represents an authorization server and its client configuration.
discovery Discovers authorization server metadata and creates a client configuration.

Grants

Function Description
authorizationCodeGrant Processes an authorization response and performs the Authorization Code Grant.
clientCredentialsGrant Performs an OAuth 2.0 Client Credentials Grant.
genericGrantRequest Performs an arbitrary OAuth grant request.
initiateBackchannelAuthentication Initiates a Client-Initiated Backchannel Authentication request.
initiateDeviceAuthorization Initiates an OAuth 2.0 Device Authorization Grant.
pollBackchannelAuthenticationGrant Polls until a Client-Initiated Backchannel Authentication Grant completes.
pollDeviceAuthorizationGrant Polls until an OAuth 2.0 Device Authorization Grant completes.
refreshTokenGrant Performs an OAuth 2.0 Refresh Token Grant.

Advanced Configuration

Function Description
allowInsecureRequests By default the module only allows interactions with HTTPS endpoints. This removes that restriction.
dynamicClientRegistration Discovers an authorization server and dynamically registers a client.
enableDecryptingResponses Enables processing of encrypted authorization server responses.
enableDetachedSignatureResponseChecks Enables FAPI 1.0 Advanced detached-signature response validation.
enableNonRepudiationChecks Enables JWS signature validation for processed JWT responses.
getJwksCache Exports the JSON Web Key Set cache used for signature validation.
setJwksCache Imports an externally managed JSON Web Key Set cache.
useCodeIdTokenResponseType Configures the client to use the OpenID Connect Hybrid Flow.
useIdTokenResponseType Configures the client to use the OpenID Connect Implicit Flow.
useJwtResponseMode Configures the client to use JWT Secured Authorization Response Mode (JARM).

Client Authentication Methods

Function Description
ClientSecretBasic Creates a client_secret_basic client authentication method.
ClientSecretJwt Creates a client_secret_jwt client authentication method.
ClientSecretPost Creates a client_secret_post client authentication method.
None Creates a none client authentication method.
PrivateKeyJwt Creates a private_key_jwt client authentication method.
TlsClientAuth Creates a tls_client_auth client authentication method.

Errors

Class Description
AuthorizationResponseError Thrown when an OAuth 2.0 Authorization Error Response is encountered.
ClientError An error raised by openid-client.
ResponseBodyError Thrown when a server returns an OAuth-style error in a JSON response body.
WWWAuthenticateChallengeError Thrown when a server response contains one or more parseable WWW-Authenticate challenges.

Authorization Request

Function Description
buildAuthorizationUrl Builds an authorization request URL.
buildAuthorizationUrlWithJAR Builds an authorization request URL using a JWT Secured Authorization Request (JAR).
buildAuthorizationUrlWithPAR Builds an authorization request URL using Pushed Authorization Requests (PAR).
calculatePKCECodeChallenge Calculates an S256 PKCE code_challenge from a code_verifier.
randomNonce Generates a random OpenID Connect nonce value.
randomState Generates a random OAuth 2.0 state value.

DPoP

Function Description
getDPoPHandle Creates a DPoP handle for sender-constrained token requests.
randomDPoPKeyPair Generates an asymmetric key pair for signing DPoP proofs.

Dynamic Client Registration (DCR)

Function Description
dynamicClientRegistration Discovers an authorization server and dynamically registers a client.

OpenID Connect 1.0

Function Description
authorizationCodeGrant Processes an authorization response and performs the Authorization Code Grant.
buildEndSessionUrl Builds an RP-Initiated Logout URL.
discovery Discovers authorization server metadata and creates a client configuration.
fetchUserInfo Fetches and parses OpenID Connect UserInfo claims.
implicitAuthentication Validates an OpenID Connect Implicit Flow response.

PKCE

Function Description
authorizationCodeGrant Processes an authorization response and performs the Authorization Code Grant.
calculatePKCECodeChallenge Calculates an S256 PKCE code_challenge from a code_verifier.
randomPKCECodeVerifier Generates a random PKCE code_verifier value.

Protected Resource Requests

Function Description
fetchProtectedResource Fetches an arbitrary OAuth 2.0 protected resource.
fetchUserInfo Fetches and parses OpenID Connect UserInfo claims.

Token Management

Function Description
tokenIntrospection Retrieves the status and metadata of an OAuth 2.0 token.
tokenRevocation Requests revocation of an OAuth 2.0 token.

Interfaces

Interface Description
AuthorizationCodeGrantChecks Expected values and validation checks for an Authorization Code Grant response.
AuthorizationCodeGrantOptions Options for performing an Authorization Code Grant.
AuthorizationDetails An entry in an OAuth 2.0 Rich Authorization Requests authorization_details array.
BackchannelAuthenticationGrantPollOptions Options for polling a Client-Initiated Backchannel Authentication Grant.
BackchannelAuthenticationResponse A parsed successful Client-Initiated Backchannel Authentication response.
ConfigurationMethods Methods exposed by a Configuration instance.
ConfigurationProperties Configurable properties exposed by a Configuration instance.
ConfirmationClaims Proof-of-possession confirmation (cnf) claims associated with a token.
CryptoKeyPair An asymmetric public and private CryptoKey pair.
CustomFetchOptions Options passed to a custom HTTP request implementation.
DecryptionKey An asymmetric private key and optional JOSE metadata used to decrypt responses.
DeviceAuthorizationGrantPollOptions Options for polling an OAuth 2.0 Device Authorization Grant.
DeviceAuthorizationResponse A parsed successful OAuth 2.0 Device Authorization Response.
DiscoveryRequestOptions Options for authorization server metadata discovery.
DPoPHandle A DPoP proof-generation and nonce-management handle returned by getDPoPHandle.
DPoPOptions Options for making DPoP-bound requests.
DynamicClientRegistrationRequestOptions Options for Dynamic Client Registration requests.
ExportedJWKSCache A JSON Web Key Set cache value suitable for external persistence.
GenerateKeyPairOptions Options for generating an asymmetric signing key pair.
IDToken Claims from a validated OpenID Connect ID Token.
ImplicitAuthenticationResponseChecks Expected values and validation checks for an OpenID Connect Implicit Flow response.
IntrospectionResponse A parsed successful OAuth 2.0 Token Introspection response.
JWKS A JSON Web Key Set.
ModifyAssertionFunction A callback that mutates a JWT assertion header and claims immediately before signing.
ModifyAssertionOptions Options for customizing a JWT assertion immediately before signing.
MTLSEndpointAliases Authorization server endpoint aliases used for mutual TLS.
PrivateKey An asymmetric private key with an optional JWK Key ID for JOSE headers.
ServerMetadataHelpers Helpers for querying authorization server capabilities.
TokenEndpointResponse A parsed successful OAuth 2.0 token endpoint response.
TokenEndpointResponseHelpers Helpers attached to a parsed TokenEndpointResponse.
UserInfoAddress The structured address claim in an OpenID Connect UserInfo response.
UserInfoResponse Claims from a parsed OpenID Connect UserInfo response.
WWWAuthenticateChallenge A parsed WWW-Authenticate challenge.
WWWAuthenticateChallengeParameters Known and extension authentication parameters from a WWW-Authenticate challenge.

Type Aliases

Type Alias Description
ClientAuth A function that applies client authentication to an authorization server request.
CryptoKey A Web Cryptography key as declared by the host runtime.
CustomFetch A Fetch API-compatible function used for outbound HTTP requests.
FetchBody A request body supported by openid-client's Fetch API integration.
JsonArray A JSON array.
JsonObject A JSON object.
JsonPrimitive A JSON primitive value.
JsonValue Any JSON-compatible value.
JWK A JSON Web Key with standard JOSE and supported extension parameters.
JWSAlgorithm A supported JWS alg identifier for digital signature validation.
OmitSymbolProperties Removes symbol-keyed properties from a type.

Variables

Variable Description
clockSkew Adjusts the current time used by protocol validations.
clockTolerance Sets the allowed clock tolerance for JWT timestamp claim validation.
customFetch Overrides the Fetch API implementation used for outbound HTTP requests.
modifyAssertion Provides a hook for mutating JWT headers and claims immediately before signing.
skipStateCheck Skips authorization response state validation.
skipSubjectCheck Skips UserInfo sub claim validation.