curl https://connect.hopae.com/.well-known/openid-configuration
{
"issuer": "https://connect.hopae.com",
"authorization_endpoint": "https://connect.hopae.com/auth",
"token_endpoint": "https://connect.hopae.com/token",
"userinfo_endpoint": "https://connect.hopae.com/userinfo",
"jwks_uri": "https://connect.hopae.com/jwks",
"scopes_supported": ["openid", "hopae", "idv", "profile", "email", "phone", "address"],
"response_types_supported": ["code id_token", "code", "id_token", "none"],
"grant_types_supported": ["implicit", "authorization_code", "refresh_token"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post", "none"],
"code_challenge_methods_supported": ["S256"],
"id_token_signing_alg_values_supported": ["ES256", "RS256"],
"authorization_response_iss_parameter_supported": true
}
OIDC
Discovery Document
OIDC discovery metadata. Served at the root of the OIDC host, not under /v2.
GET
/
.well-known
/
openid-configuration
curl https://connect.hopae.com/.well-known/openid-configuration
{
"issuer": "https://connect.hopae.com",
"authorization_endpoint": "https://connect.hopae.com/auth",
"token_endpoint": "https://connect.hopae.com/token",
"userinfo_endpoint": "https://connect.hopae.com/userinfo",
"jwks_uri": "https://connect.hopae.com/jwks",
"scopes_supported": ["openid", "hopae", "idv", "profile", "email", "phone", "address"],
"response_types_supported": ["code id_token", "code", "id_token", "none"],
"grant_types_supported": ["implicit", "authorization_code", "refresh_token"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post", "none"],
"code_challenge_methods_supported": ["S256"],
"id_token_signing_alg_values_supported": ["ES256", "RS256"],
"authorization_response_iss_parameter_supported": true
}
The discovery document lives at the root of the OIDC host and is shared by v1 and v2. Use it for the issuer and the signing keys.
authorization_endpoint here is the v1 endpoint. For v2, start authorization at https://connect.hopae.com/v2/auth. See Base URL.Response
string
https://connect.hopae.com. The iss of every ID token and of the authorization response. The same on a custom domain.string
The v1 authorization endpoint. Replace it with
/v2/auth for v2.string
Token endpoint. Returns v2 data for verifications started on
/v2/auth.string
UserInfo endpoint. Returns v2 data for verifications started on
/v2/auth.string
Keys for validating ID tokens. Shared by sandbox and production apps.
curl https://connect.hopae.com/.well-known/openid-configuration
{
"issuer": "https://connect.hopae.com",
"authorization_endpoint": "https://connect.hopae.com/auth",
"token_endpoint": "https://connect.hopae.com/token",
"userinfo_endpoint": "https://connect.hopae.com/userinfo",
"jwks_uri": "https://connect.hopae.com/jwks",
"scopes_supported": ["openid", "hopae", "idv", "profile", "email", "phone", "address"],
"response_types_supported": ["code id_token", "code", "id_token", "none"],
"grant_types_supported": ["implicit", "authorization_code", "refresh_token"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post", "none"],
"code_challenge_methods_supported": ["S256"],
"id_token_signing_alg_values_supported": ["ES256", "RS256"],
"authorization_response_iss_parameter_supported": true
}
The document lists what the server software supports, not what your app is registered for. Your app uses
response_type=code, grant_type=authorization_code, and client_secret_basic or client_secret_post. PKCE (S256) is optional. Refresh tokens are never issued.Authorizations
Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Response
200 - application/json
Provider metadata.
https://connect.hopae.com, with no path. Shared by sandbox and production apps. The client id selects the app.
Keys for validating ID tokens.

