Endpoint reference

The public OIDC endpoints, scopes, and claims; discovery remains authoritative.

PandaAuth’s protocol endpoints and metadata follow standard OIDC/OAuth 2.0. This page is a quick reference; the single source of truth is always the discovery document:

https://<your-auth-domain>/.well-known/openid-configuration

Public key set (JWKS): /.well-known/jwks.

Core endpoints

Endpoint Purpose
/connect/authorize Entry point of the authorization code flow (browser redirect)
/connect/token Exchange an authorization code / refresh token / client credentials for tokens
/connect/userinfo Returns user information per the granted scopes
/connect/logout RP-initiated end session (together with post_logout_redirect_uri)
/connect/introspect Token introspection (requires the registered introspection permission; typically used by resource servers)
/connect/revoke Token revocation

Scope

Scope Description
openid Required; authentication
profile Basic profile (includes the nickname claim)
email Email address
roles Role claims (such as admin), written into access tokens
offline_access Refresh token
Custom business scopes Such as api; constrained by the client’s declared permissions

Notes on claims

  • Claims such as roles and nickname are issued with the token (subject to the roles / profile scope grants); resource services should verify the access token’s signature (JWKS) before trusting its claims;
  • After a user’s profile or roles change, claims in existing access tokens are not backfilled — administrative changes immediately revoke existing tokens, so new tokens carrying the new claims are obtained naturally (see Security facts).

Management operations

Use the admin console to manage users and clients. A public Management API for integrators is not currently available; see Management API availability for details.