Endpoint reference
The public OIDC endpoints, scopes, and claims; discovery remains authoritative.
PandaAuth’s protocol endpoints and metadata follow standard OIDC/OAuth 2.0. This page is a quick reference; the single source of truth is always the discovery document:
https://<your-auth-domain>/.well-known/openid-configuration
Public key set (JWKS): /.well-known/jwks.
Core endpoints
| Endpoint | Purpose |
|---|---|
/connect/authorize |
Entry point of the authorization code flow (browser redirect) |
/connect/token |
Exchange an authorization code / refresh token / client credentials for tokens |
/connect/userinfo |
Returns user information per the granted scopes |
/connect/logout |
RP-initiated end session (together with post_logout_redirect_uri) |
/connect/introspect |
Token introspection (requires the registered introspection permission; typically used by resource servers) |
/connect/revoke |
Token revocation |
Scope
| Scope | Description |
|---|---|
openid |
Required; authentication |
profile |
Basic profile (includes the nickname claim) |
email |
Email address |
roles |
Role claims (such as admin), written into access tokens |
offline_access |
Refresh token |
| Custom business scopes | Such as api; constrained by the client’s declared permissions |
Notes on claims
- Claims such as roles and nickname are issued with the token (subject to the
roles/profilescope grants); resource services should verify the access token’s signature (JWKS) before trusting its claims; - After a user’s profile or roles change, claims in existing access tokens are not backfilled — administrative changes immediately revoke existing tokens, so new tokens carrying the new claims are obtained naturally (see Security facts).
Management operations
Use the admin console to manage users and clients. A public Management API for integrators is not currently available; see Management API availability for details.