Skip to main content

OpenID Provider (Sandbox organisation)

📄️ Authorisation Endpoint

Starts the authorisation flow. Takes the same parameters as the GET request, in a form encoded body. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to `redirect_uri` with `code` and `state`. When the individual does not answer within 15 minutes, the page redirects with `error=interaction_required`. The endpoint accepts GET and POST.

📄️ Token Endpoint

OpenID Connect token endpoint that exchanges an authorisation code for access and ID tokens. Client authentication is required using HTTP Basic Auth with `client_id` as username and `client_secret` as password. The `sub` value is resolved during this request, with the identity matching attributes or the callback of the client. The ID token holds the claims `iss`, `sub`, `aud`, `presentation`, `iat` and `exp`, and `nonce` when the authorisation request had one. The access token and the ID token expire after 5 minutes.