# Standards support

> Check which OAuth 2.0 and OpenID Connect standards and features OneiD supports, which it does not, and what to use instead.

Source: https://oltinid.com/docs/reference/standards-support/ · Section: Reference · All OneiD documentation: https://oltinid.com/llms.txt

This page lists the standards and features OneiD supports and the ones it does not. For each unsupported item it says what to do instead. If something you need is not listed, ask your OneiD administrator or [talk to us](https://oltinid.com/contact/?topic=organisation).

## Conformance testing

OneiD was tested with the OpenID Foundation's conformance suite, using the Config, Basic, Form Post and RP-Initiated Logout provider test plans, with no failed test. This is a test result, not a certification.

## Specifications

| Specification | Status | Note or alternative |
|---|---|---|
| OAuth 2.0 (RFC 6749) | Supported | Authorization code, client credentials and refresh token grants. |
| PKCE (RFC 7636) | Supported | `S256`. Required for public clients and, by default, for confidential clients. |
| Bearer token usage (RFC 6750) | Supported | Send access tokens in the `Authorization: Bearer` header. |
| JSON Web Token (RFC 7519) | Supported | ID tokens and access tokens are JWTs signed with RS256. |
| Token introspection (RFC 7662) | Supported | Confidential clients only, for tokens issued to the calling client. |
| Token revocation (RFC 7009) | Supported | Revokes refresh tokens and access tokens in OneiD's store. |
| Authorization server issuer identification (RFC 9207) | Supported | Authorisation responses include `iss`. |
| OpenID Connect Core 1.0 | Supported | Code flow, ID tokens, userinfo, `prompt`, `max_age`, `claims` parameter. |
| OpenID Connect Discovery 1.0 | Supported | `/.well-known/openid-configuration`. |
| OpenID Connect RP-Initiated Logout 1.0 | Supported | `/connect/logout`. |
| OAuth 2.0 Form Post Response Mode | Supported | `response_mode=form_post`. |
| OpenID Connect Dynamic Client Registration | Not supported | An administrator registers clients in the admin console or through the Admin API. |
| OpenID Connect Session Management | Not supported | No `check_session_iframe`. Use `prompt=none` checks or refresh failures to notice a session end. |
| OpenID Connect Front-Channel Logout | Not supported | Other applications are not notified at sign-out. Keep application sessions short. |
| OpenID Connect Back-Channel Logout | Not supported | As above. |
| Pushed authorization requests, PAR (RFC 9126) | Not supported | Send parameters directly in the authorisation request. |
| JWT-secured authorization requests, JAR (RFC 9101) | Not supported | `request` and `request_uri` are answered with `request_not_supported` and `request_uri_not_supported`. Send parameters directly. |
| DPoP (RFC 9449) | Not supported | Use bearer tokens over TLS with short lifetimes. |
| Mutual TLS client authentication and certificate-bound tokens (RFC 8705) | Not supported | Authenticate with a client secret. |
| Token exchange (RFC 8693) | Not supported | Use client credentials for service-to-service calls. |
| Device authorization grant (RFC 8628) | Not supported | OneiD has no flow for devices without a browser. On devices with a browser, use authorization code with PKCE. |
| Client-initiated backchannel authentication, CIBA | Not supported | No alternative in OneiD. |
| Resource indicators (RFC 8707) | Not supported | Access tokens have no `aud`. APIs check issuer, signature, expiry and scope. |
| SAML 2.0 | Not supported | Connect applications with OpenID Connect. Upstream identity providers must speak OpenID Connect. |
| WS-Federation | Not supported | Connect applications with OpenID Connect. |
| SCIM | Not supported | Manage users through the admin console or the [Admin API](https://oltinid.com/docs/operate/admin-api/). |

## Grants and flows

| Grant or flow | Status | Note or alternative |
|---|---|---|
| Authorization code with PKCE | Supported | For every application that signs users in. |
| Refresh token | Supported | Request `offline_access`; the client needs the refresh_token grant. Rotated on every use. |
| Client credentials | Supported | Confidential clients only. No refresh token. |
| Implicit | Not supported | Use authorization code with PKCE. |
| Hybrid | Not supported | Use authorization code with PKCE. |
| Resource owner password credentials (password) | Not supported | Use authorization code with PKCE. |
| Device code | Not supported | See device authorization grant above. |
| Token exchange | Not supported | See above. |
| CIBA | Not supported | See above. |

## Client authentication

| Method | Status | Note or alternative |
|---|---|---|
| `client_secret_basic` | Supported | Recommended for confidential clients. |
| `client_secret_post` | Supported | Accepted. |
| Public client (`client_id` only, no secret) | Supported | For browser, mobile and desktop applications, with PKCE. |
| `private_key_jwt` | Not supported | Listed in discovery, but there is no way to register a client's public key. Use a client secret. |
| `tls_client_auth`, `self_signed_tls_client_auth` | Not supported | Use a client secret. |

## Response types, modes and PKCE methods

| Item | Status | Note or alternative |
|---|---|---|
| `response_type=code` | Supported | The only response type. |
| `response_mode=query` | Supported | The default. |
| `response_mode=form_post` | Supported | |
| `response_mode=fragment` | Not recommended | Listed in discovery but not recommended or tested. Use `query` or `form_post`. |
| `code_challenge_method=S256` | Supported | Always use it. |
| `code_challenge_method=plain` | Do not use | Listed in discovery. Use `S256`. |

## Tokens

| Item | Status | Note or alternative |
|---|---|---|
| JWT access tokens, RS256 | Supported | With `kid` matching the JWKS. |
| ID tokens, RS256 | Supported | The only signing algorithm. |
| Opaque refresh tokens and authorization codes | Supported | Never parse them. |
| `aud` claim in access tokens | Not supported | APIs must not require an audience. Check scope instead. |
| Encrypted tokens (JWE) | Not supported | Tokens are signed, not encrypted. Keep them out of URLs and logs. |
| Pairwise subject identifiers | Not supported | `subject_types_supported` is `public`. |
| Signing key rotation | Supported | New keys are published before use; retired keys stay in the JWKS for 30 days. |

## Scopes and claims

| Item | Status | Note or alternative |
|---|---|---|
| `openid`, `profile`, `email`, `phone`, `roles`, `offline_access` | Supported | See [Claims](https://oltinid.com/docs/reference/claims/). |
| Custom API scopes | Supported | Created by an administrator. Appear in the access token's `scope` claim. |
| `address` scope | Not supported | Keep postal addresses in your application. |
| `sid` claim | Not supported | |
| `claims` request parameter | Supported | `id_token` and `userinfo` members. Claim names are read; `essential`, `value` and `values` are ignored. |

## Authorisation request parameters

| Parameter | Status | Note or alternative |
|---|---|---|
| `state`, `nonce` | Supported | Recommended on every request. |
| `prompt=none`, `login`, `select_account`, `consent` | Supported | `select_account` forces a new sign-in; there is no account picker. |
| `max_age` | Supported | Compared with `auth_time`. |
| `id_token_hint` | Supported | A different user from the one signed in forces sign-in. |
| `login_hint` | Not honoured | Accepted with no effect. The user enters their user name. |
| `ui_locales` | Not honoured | Sign-in pages are in English. |
| `display` | Not honoured | Accepted with no effect. |
| `acr_values` | Not enforced | Accepted with no effect. Check `acr` or `amr` in the ID token, and ask your administrator to make MFA mandatory. |
| `request`, `request_uri` | Not supported | See JAR above. |

## Sessions and sign-out

| Item | Status | Note or alternative |
|---|---|---|
| Single sign-on across applications | Supported | Through the OneiD browser session (8 hours, extended while active). |
| RP-initiated logout | Supported | See [Sign-out](https://oltinid.com/docs/guides/logout/). |
| Sign-out at an upstream OpenID Connect provider | Supported | Sign-out continues to the provider. |
| Front-channel and back-channel logout | Not supported | Use short application sessions, `prompt=none` checks or refresh failures. |
| Session management iframe | Not supported | As above. |

## Multi-factor authentication

| Method | Status | Note or alternative |
|---|---|---|
| Authenticator app (TOTP, 6 digits, 30 seconds) | Supported | Optional or mandatory, for everyone or per user. Applies to OneiD accounts and LDAP users. |
| Upstream provider MFA | Supported | Users from an upstream OpenID Connect provider use that provider's MFA. |
| SMS codes | Not supported | Use an authenticator app. |
| Email codes | Not supported | Use an authenticator app. |
| Push notifications | Not supported | Use an authenticator app. |
| Passkeys and WebAuthn | Not supported | Use an authenticator app. |
| Recovery codes | Not supported | If a user loses their device, an administrator resets their MFA. |

## Users, sign-in sources and federation

| Item | Status | Note or alternative |
|---|---|---|
| OneiD accounts | Supported | Created by administrators. See [OneiD accounts and MFA](https://oltinid.com/docs/sign-in-sources/oneid-accounts/). |
| LDAP and Active Directory | Supported | One directory server per deployment. See [LDAP and Active Directory](https://oltinid.com/docs/sign-in-sources/ldap/). |
| Upstream OpenID Connect provider, such as Okta | Supported | See [Okta and other OpenID Connect providers](https://oltinid.com/docs/sign-in-sources/openid-connect-provider/). |
| Microsoft Entra ID as a sign-in source | Not available | [Contact us](https://oltinid.com/contact/?topic=organisation) if you need Entra ID. |
| Several sign-in sources in one deployment | Not supported | Each deployment has one sign-in source. |
| Social-login buttons | Not supported | |
| User self-registration | Not supported | Administrators create OneiD accounts. |
| SAML identity providers | Not supported | Use an OpenID Connect provider. |
| SCIM provisioning | Not supported | Use the [Admin API](https://oltinid.com/docs/operate/admin-api/). |
| Tenants or organisations inside a deployment | Not supported | Each deployment has one issuer, one database and one user store. |

## Administration and integration

| Item | Status | Note or alternative |
|---|---|---|
| Admin console | Supported | Applications, users, roles, API scopes, sessions, audit log, signing keys, import and export of clients. |
| Admin API | Supported | Under `/api/admin/v1`. See [Automate with the Admin API](https://oltinid.com/docs/operate/admin-api/). |
| Incoming help-desk webhooks | Supported | Reset a user's password or MFA from a help-desk tool. |
| Outgoing event webhooks | Not supported | OneiD does not send events to other systems. |
| Custom logos and colours on sign-in pages | Not supported | Sign-in pages use the OneiD design. |
| Sign-in page languages other than English | Not supported | |

## Learn more

- [Discovery document](https://oltinid.com/docs/reference/discovery/)
- [Endpoints](https://oltinid.com/docs/reference/endpoints/)
- [Choose a flow](https://oltinid.com/docs/get-started/choose-a-flow/)
