Endpoint reference

The public OIDC endpoints, scopes, and claims; discovery remains authoritative.

PandaAuth’s protocol endpoints and metadata follow standard OIDC/OAuth 2.0. This page is a quick reference; the single source of truth is always the discovery document:

https://<your-auth-domain>/.well-known/openid-configuration

Public key set (JWKS): /.well-known/jwks.

Core endpoints

Endpoint Purpose
/connect/authorize Entry point of the authorization code flow (browser redirect)
/connect/token Exchange an authorization code / refresh token / client credentials for tokens
/connect/userinfo Returns user information per the granted scopes
/connect/logout RP-initiated end session (together with post_logout_redirect_uri)
/connect/introspect Token introspection (requires the registered introspection permission; typically used by resource servers)
/connect/revoke Token revocation

Scope

Scope Description
openid Required; authentication
profile Basic profile (includes the nickname claim)
email Email address
roles Role claims (such as admin), written into access tokens
offline_access Refresh token
Custom business scopes Such as api; constrained by the client’s declared permissions

Notes on claims

  • Claims such as roles and nickname are issued with the token (subject to the roles / profile scope grants); resource services should verify the access token’s signature (JWKS) before trusting its claims;
  • After a user’s profile or roles change, claims in existing access tokens are not backfilled — administrative changes immediately revoke existing tokens, so new tokens carrying the new claims are obtained naturally (see Security facts).

Management API status (stated as it is)

The user and client management APIs are currently an internal deployment channel (dedicated to the admin console BFF, not exposed at the network layer); no public Management API is offered to integrators yet. A public management API is on the roadmap (see the changelog and the community boundary statement). Until then, management actions are performed manually in the admin console.