Documentation
Build with OneiD
Sign users in to your applications and protect your APIs with OpenID Connect and OAuth 2.0. Every page is written to be followed step by step, by you or by your coding agent.
Popular:Authorization code flow with PKCEEndpointsProtect an API (validate access tokens)Errors and troubleshooting
- 1
Understand the basics
Issuer, clients, scopes and tokens: the five ideas that the rest of the docs build on.
How OneiD works - 2
Connect your first app
Pick your stack and run a complete example. Each quickstart lists the client settings it needs.
Choose a quickstart - 3
Get ready for production
Exact redirect addresses, secret handling, token validation and the errors to expect.
Security best practices
Quickstarts
A complete program for your stack, with the settings it needs and what you should see.
Browser applications
Single-page applications that run in the browser. Public client, PKCE, no secret.
Server web applications
Applications that render pages on a server and keep a session. Usually a confidential client.
APIs
Services that accept OneiD access tokens and check them without calling OneiD.
Browse by topic
Every page, grouped the way the sidebar shows them.
Get started
Concepts, your first sign-in, and how to register an application.
Guides
Flows and tasks: sign-in with PKCE, services, refresh tokens, sign-out, APIs.
Reference
Every endpoint, token, claim, error and client setting, in one place.
Sign-in sources
OneiD accounts, LDAP and Active Directory, Okta and other providers.
AI agents
Hand the docs to a coding agent and build connectors from a specification.
Operate OneiD
Run OneiD in your own environment and automate it with the Admin API.
Working with an AI coding agent?
Give it llms.txt or llms-full.txt, the connector specification and theOneiD skill file. Every page is also Markdown: add.md to its address.