Standards support

Check which OAuth 2.0 and OpenID Connect standards and features OneiD supports, which it does not, and what to use instead.

View as Markdown

This page lists the standards and features OneiD supports and the ones it does not. For each unsupported item it says what to do instead. If something you need is not listed, ask your OneiD administrator or talk to us.

Conformance testing

OneiD was tested with the OpenID Foundation’s conformance suite, using the Config, Basic, Form Post and RP-Initiated Logout provider test plans, with no failed test. This is a test result, not a certification.

Specifications

Specification Status Note or alternative
OAuth 2.0 (RFC 6749) Supported Authorization code, client credentials and refresh token grants.
PKCE (RFC 7636) Supported S256. Required for public clients and, by default, for confidential clients.
Bearer token usage (RFC 6750) Supported Send access tokens in the Authorization: Bearer header.
JSON Web Token (RFC 7519) Supported ID tokens and access tokens are JWTs signed with RS256.
Token introspection (RFC 7662) Supported Confidential clients only, for tokens issued to the calling client.
Token revocation (RFC 7009) Supported Revokes refresh tokens and access tokens in OneiD’s store.
Authorization server issuer identification (RFC 9207) Supported Authorisation responses include iss.
OpenID Connect Core 1.0 Supported Code flow, ID tokens, userinfo, prompt, max_age, claims parameter.
OpenID Connect Discovery 1.0 Supported /.well-known/openid-configuration.
OpenID Connect RP-Initiated Logout 1.0 Supported /connect/logout.
OAuth 2.0 Form Post Response Mode Supported response_mode=form_post.
OpenID Connect Dynamic Client Registration Not supported An administrator registers clients in the admin console or through the Admin API.
OpenID Connect Session Management Not supported No check_session_iframe. Use prompt=none checks or refresh failures to notice a session end.
OpenID Connect Front-Channel Logout Not supported Other applications are not notified at sign-out. Keep application sessions short.
OpenID Connect Back-Channel Logout Not supported As above.
Pushed authorization requests, PAR (RFC 9126) Not supported Send parameters directly in the authorisation request.
JWT-secured authorization requests, JAR (RFC 9101) Not supported request and request_uri are answered with request_not_supported and request_uri_not_supported. Send parameters directly.
DPoP (RFC 9449) Not supported Use bearer tokens over TLS with short lifetimes.
Mutual TLS client authentication and certificate-bound tokens (RFC 8705) Not supported Authenticate with a client secret.
Token exchange (RFC 8693) Not supported Use client credentials for service-to-service calls.
Device authorization grant (RFC 8628) Not supported OneiD has no flow for devices without a browser. On devices with a browser, use authorization code with PKCE.
Client-initiated backchannel authentication, CIBA Not supported No alternative in OneiD.
Resource indicators (RFC 8707) Not supported Access tokens have no aud. APIs check issuer, signature, expiry and scope.
SAML 2.0 Not supported Connect applications with OpenID Connect. Upstream identity providers must speak OpenID Connect.
WS-Federation Not supported Connect applications with OpenID Connect.
SCIM Not supported Manage users through the admin console or the Admin API.

Grants and flows

Grant or flow Status Note or alternative
Authorization code with PKCE Supported For every application that signs users in.
Refresh token Supported Request offline_access; the client needs the refresh_token grant. Rotated on every use.
Client credentials Supported Confidential clients only. No refresh token.
Implicit Not supported Use authorization code with PKCE.
Hybrid Not supported Use authorization code with PKCE.
Resource owner password credentials (password) Not supported Use authorization code with PKCE.
Device code Not supported See device authorization grant above.
Token exchange Not supported See above.
CIBA Not supported See above.

Client authentication

Method Status Note or alternative
client_secret_basic Supported Recommended for confidential clients.
client_secret_post Supported Accepted.
Public client (client_id only, no secret) Supported For browser, mobile and desktop applications, with PKCE.
private_key_jwt Not supported Listed in discovery, but there is no way to register a client’s public key. Use a client secret.
tls_client_auth, self_signed_tls_client_auth Not supported Use a client secret.

Response types, modes and PKCE methods

Item Status Note or alternative
response_type=code Supported The only response type.
response_mode=query Supported The default.
response_mode=form_post Supported
response_mode=fragment Not recommended Listed in discovery but not recommended or tested. Use query or form_post.
code_challenge_method=S256 Supported Always use it.
code_challenge_method=plain Do not use Listed in discovery. Use S256.

Tokens

Item Status Note or alternative
JWT access tokens, RS256 Supported With kid matching the JWKS.
ID tokens, RS256 Supported The only signing algorithm.
Opaque refresh tokens and authorization codes Supported Never parse them.
aud claim in access tokens Not supported APIs must not require an audience. Check scope instead.
Encrypted tokens (JWE) Not supported Tokens are signed, not encrypted. Keep them out of URLs and logs.
Pairwise subject identifiers Not supported subject_types_supported is public.
Signing key rotation Supported New keys are published before use; retired keys stay in the JWKS for 30 days.

Scopes and claims

Item Status Note or alternative
openid, profile, email, phone, roles, offline_access Supported See Claims.
Custom API scopes Supported Created by an administrator. Appear in the access token’s scope claim.
address scope Not supported Keep postal addresses in your application.
sid claim Not supported
claims request parameter Supported id_token and userinfo members. Claim names are read; essential, value and values are ignored.

Authorisation request parameters

Parameter Status Note or alternative
state, nonce Supported Recommended on every request.
prompt=none, login, select_account, consent Supported select_account forces a new sign-in; there is no account picker.
max_age Supported Compared with auth_time.
id_token_hint Supported A different user from the one signed in forces sign-in.
login_hint Not honoured Accepted with no effect. The user enters their user name.
ui_locales Not honoured Sign-in pages are in English.
display Not honoured Accepted with no effect.
acr_values Not enforced Accepted with no effect. Check acr or amr in the ID token, and ask your administrator to make MFA mandatory.
request, request_uri Not supported See JAR above.

Sessions and sign-out

Item Status Note or alternative
Single sign-on across applications Supported Through the OneiD browser session (8 hours, extended while active).
RP-initiated logout Supported See Sign-out.
Sign-out at an upstream OpenID Connect provider Supported Sign-out continues to the provider.
Front-channel and back-channel logout Not supported Use short application sessions, prompt=none checks or refresh failures.
Session management iframe Not supported As above.

Multi-factor authentication

Method Status Note or alternative
Authenticator app (TOTP, 6 digits, 30 seconds) Supported Optional or mandatory, for everyone or per user. Applies to OneiD accounts and LDAP users.
Upstream provider MFA Supported Users from an upstream OpenID Connect provider use that provider’s MFA.
SMS codes Not supported Use an authenticator app.
Email codes Not supported Use an authenticator app.
Push notifications Not supported Use an authenticator app.
Passkeys and WebAuthn Not supported Use an authenticator app.
Recovery codes Not supported If a user loses their device, an administrator resets their MFA.

Users, sign-in sources and federation

Item Status Note or alternative
OneiD accounts Supported Created by administrators. See OneiD accounts and MFA.
LDAP and Active Directory Supported One directory server per deployment. See LDAP and Active Directory.
Upstream OpenID Connect provider, such as Okta Supported See Okta and other OpenID Connect providers.
Microsoft Entra ID as a sign-in source Not available Contact us if you need Entra ID.
Several sign-in sources in one deployment Not supported Each deployment has one sign-in source.
Social-login buttons Not supported
User self-registration Not supported Administrators create OneiD accounts.
SAML identity providers Not supported Use an OpenID Connect provider.
SCIM provisioning Not supported Use the Admin API.
Tenants or organisations inside a deployment Not supported Each deployment has one issuer, one database and one user store.

Administration and integration

Item Status Note or alternative
Admin console Supported Applications, users, roles, API scopes, sessions, audit log, signing keys, import and export of clients.
Admin API Supported Under /api/admin/v1. See Automate with the Admin API.
Incoming help-desk webhooks Supported Reset a user’s password or MFA from a help-desk tool.
Outgoing event webhooks Not supported OneiD does not send events to other systems.
Custom logos and colours on sign-in pages Not supported Sign-in pages use the OneiD design.
Sign-in page languages other than English Not supported

Learn more