Endpoint reference
The public OIDC endpoints, scopes, and claims; discovery remains authoritative.
PandaAuth’s protocol endpoints and metadata follow standard OIDC/OAuth 2.0. This page is a quick reference; the single source of truth is always the discovery document:
https://<your-auth-domain>/.well-known/openid-configuration
Public key set (JWKS): /.well-known/jwks.
Core endpoints
| Endpoint | Purpose |
|---|---|
/connect/authorize |
Entry point of the authorization code flow (browser redirect) |
/connect/token |
Exchange an authorization code / refresh token / client credentials for tokens |
/connect/userinfo |
Returns user information per the granted scopes |
/connect/logout |
RP-initiated end session (together with post_logout_redirect_uri) |
/connect/introspect |
Token introspection (requires the registered introspection permission; typically used by resource servers) |
/connect/revoke |
Token revocation |
Scope
| Scope | Description |
|---|---|
openid |
Required; authentication |
profile |
Basic profile (includes the nickname claim) |
email |
Email address |
roles |
Role claims (such as admin), written into access tokens |
offline_access |
Refresh token |
| Custom business scopes | Such as api; constrained by the client’s declared permissions |
Notes on claims
- Claims such as roles and nickname are issued with the token (subject to the
roles/profilescope grants); resource services should verify the access token’s signature (JWKS) before trusting its claims; - After a user’s profile or roles change, claims in existing access tokens are not backfilled — administrative changes immediately revoke existing tokens, so new tokens carrying the new claims are obtained naturally (see Security facts).
Management API status (stated as it is)
The user and client management APIs are currently an internal deployment channel (dedicated to the admin console BFF, not exposed at the network layer); no public Management API is offered to integrators yet. A public management API is on the roadmap (see the changelog and the community boundary statement). Until then, management actions are performed manually in the admin console.