📄️ Authorisation Endpoint
OpenID Connect authorisation endpoint that initiates the authentication flow. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to `redirect_uri` with `code` and `state`. When the individual does not answer within 15 minutes, the page redirects with `error=interaction_required`. The endpoint accepts GET and POST.
📄️ Authorisation Endpoint
Starts the authorisation flow. Takes the same parameters as the GET request, in a form encoded body. Returns an HTML page where individuals can authenticate using their EUDI Wallet through QR code or deep link verification. After the individual presents the credentials, the page redirects the browser to `redirect_uri` with `code` and `state`. When the individual does not answer within 15 minutes, the page redirects with `error=interaction_required`. The endpoint accepts GET and POST.
📄️ Token Endpoint
OpenID Connect token endpoint that exchanges an authorisation code for access and ID tokens. Client authentication is required using HTTP Basic Auth with `client_id` as username and `client_secret` as password. The `sub` value is resolved during this request, with the identity matching attributes or the callback of the client. The ID token holds the claims `iss`, `sub`, `aud`, `presentation`, `iat` and `exp`, and `nonce` when the authorisation request had one. The access token and the ID token expire after 5 minutes.
📄️ UserInfo Endpoint
OpenID Connect UserInfo endpoint that returns claims about the authenticated end-user. Requires a valid access token obtained from the token endpoint to be provided in the `Authorization` header. The endpoint accepts GET and POST. Error answers of the provider have an empty body, and the `WWW-Authenticate` header holds the reason.
📄️ Discovery Endpoint
OpenID Provider configuration endpoint that returns the OpenID Provider metadata as a JSON document
📄️ JWKS Endpoint
JSON Web Key Set (JWKS) endpoint that provides the public keys used to verify the signatures of JWT tokens issued by this OpenID Provider. These keys are used by relying parties to validate ID tokens and other signed responses.