Skip to main content
GET
The discovery document lives at the root of the OIDC host and is shared by v1 and v2. Use it for the issuer and the signing keys.
authorization_endpoint here is the v1 endpoint. For v2, start authorization at https://connect.hopae.com/v2/auth. See Base URL.

Response

string
https://connect.hopae.com. The iss of every ID token and of the authorization response. The same on a custom domain.
string
The v1 authorization endpoint. Replace it with /v2/auth for v2.
string
Token endpoint. Returns v2 data for verifications started on /v2/auth.
string
UserInfo endpoint. Returns v2 data for verifications started on /v2/auth.
string
Keys for validating ID tokens. Shared by sandbox and production apps.
The document lists what the server software supports, not what your app is registered for. Your app uses response_type=code, grant_type=authorization_code, and client_secret_basic or client_secret_post. PKCE (S256) is optional. Refresh tokens are never issued.

Authorizations

Authorization
string
header
required

Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.

Response

200 - application/json

Provider metadata.

issuer
string

https://connect.hopae.com, with no path. Shared by sandbox and production apps. The client id selects the app.

authorization_endpoint
string
token_endpoint
string
userinfo_endpoint
string
jwks_uri
string

Keys for validating ID tokens.

scopes_supported
string[]
response_types_supported
string[]