Only the safe flows
Authorization code with PKCE for every application with a user, client credentials for services. The implicit flow and the password grant are not available, so they cannot be misused.
Security
An identity service holds the keys to every application behind it. OneiD is built so that the safe choice is the default and the unsafe one is not on offer.
Controls
Each of these is part of OneiD as it ships, not an option you have to find.
Authorization code with PKCE for every application with a user, client credentials for services. The implicit flow and the password grant are not available, so they cannot be misused.
RSA keys stored encrypted, rotated from the console and published before they sign. Retired keys stay published long enough for issued tokens to remain verifiable.
Signing keys, authenticator secrets and session cookies are protected by an encrypted key ring. Passwords are stored only as salted, deliberately slow hashes, or not at all when a directory checks them.
Authenticator-app codes with QR enrolment, optional or mandatory. Replayed codes are refused, and turning the factor off needs proof and sends an email.
Accounts lock after repeated wrong passwords or codes, and rate limits apply per address and per account to sign-in, second factors, password recovery and the token endpoint.
A failed sign-in gives the same answer whether the account is unknown or locked, so attackers cannot probe for accounts.
Tokens are revoked when a user signs out of an application, changes the password, loses a role, is locked, or when a client is disabled.
Separate administrator roles, read-only versions, and privileged scopes that only a full administrator can grant.
HTTPS only with HSTS, a Content-Security-Policy with per-request nonces, no framing, no referrer, CSRF protection, and sign-out by POST only.
Sign-ins, failures, second factors, password and role changes, client changes and key rotations are recorded with time and address.
Logs never contain passwords, secrets or tokens, and identifiers are masked. Client secrets can carry an expiry date that OneiD enforces.
The OpenID Foundation’s conformance suite ran the Config, Basic, Form Post and RP-Initiated Logout provider plans with no failed test.
Certifications
OneiD was tested with the OpenID Foundation’s conformance suite. These are the certifications we are working towards.
Shared responsibility
Tell us privately through the contact form, with the steps to reproduce it. Please do not test against other people’s accounts or data. Our contact details are also insecurity.txt.
Security reviews are welcome. Tell us what your assessment needs and we will walk your team through how OneiD works.