> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hopae.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Discovery Document

> OIDC discovery metadata. Served at the root of the OIDC host, not under /v2.

The discovery document lives at the root of the OIDC host and is shared by v1 and v2. Use it for the issuer and the signing keys.

<Warning>
  `authorization_endpoint` here is the v1 endpoint. For v2, start authorization at `https://connect.hopae.com/v2/auth`. See [Base URL](/v2/api-reference/oidc/base-url).
</Warning>

## Response

<ResponseField name="issuer" type="string">
  `https://connect.hopae.com`. The `iss` of every ID token and of the authorization response. The same on a [custom domain](/v2/guides/concepts/custom-domain).
</ResponseField>

<ResponseField name="authorization_endpoint" type="string">
  The v1 authorization endpoint. Replace it with `/v2/auth` for v2.
</ResponseField>

<ResponseField name="token_endpoint" type="string">
  Token endpoint. Returns v2 data for verifications started on `/v2/auth`.
</ResponseField>

<ResponseField name="userinfo_endpoint" type="string">
  UserInfo endpoint. Returns v2 data for verifications started on `/v2/auth`.
</ResponseField>

<ResponseField name="jwks_uri" type="string">
  Keys for validating ID tokens. Shared by sandbox and production apps.
</ResponseField>

<RequestExample>
  ```bash theme={null}
  curl https://connect.hopae.com/.well-known/openid-configuration
  ```
</RequestExample>

<ResponseExample>
  ```json Response (abridged) theme={null}
  {
    "issuer": "https://connect.hopae.com",
    "authorization_endpoint": "https://connect.hopae.com/auth",
    "token_endpoint": "https://connect.hopae.com/token",
    "userinfo_endpoint": "https://connect.hopae.com/userinfo",
    "jwks_uri": "https://connect.hopae.com/jwks",
    "scopes_supported": ["openid", "hopae", "idv", "profile", "email", "phone", "address"],
    "response_types_supported": ["code id_token", "code", "id_token", "none"],
    "grant_types_supported": ["implicit", "authorization_code", "refresh_token"],
    "token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post", "none"],
    "code_challenge_methods_supported": ["S256"],
    "id_token_signing_alg_values_supported": ["ES256", "RS256"],
    "authorization_response_iss_parameter_supported": true
  }
  ```
</ResponseExample>

<Note>
  The document lists what the server software supports, not what your app is registered for. Your app uses `response_type=code`, `grant_type=authorization_code`, and `client_secret_basic` or `client_secret_post`. PKCE (`S256`) is optional. Refresh tokens are never issued.
</Note>


## OpenAPI

````yaml GET /.well-known/openid-configuration
openapi: 3.1.0
info:
  title: Hopae Connect OpenID Provider
  version: 2.0.0
servers:
  - url: https://connect.hopae.com/v2
    description: Hopae Connect
security: []
tags:
  - name: OIDC
paths:
  /.well-known/openid-configuration:
    servers:
      - url: https://connect.hopae.com
        description: Hopae Connect (discovery and keys live at the root)
    get:
      tags:
        - OIDC
      summary: Discovery Document
      operationId: discovery
      parameters: []
      responses:
        '200':
          description: Provider metadata.
          content:
            application/json:
              schema:
                type: object
                properties:
                  issuer:
                    type: string
                    description: >-
                      `https://connect.hopae.com`, with no path. Shared by
                      sandbox and production apps. The client id selects the
                      app.
                  authorization_endpoint:
                    type: string
                  token_endpoint:
                    type: string
                  userinfo_endpoint:
                    type: string
                  jwks_uri:
                    type: string
                    description: Keys for validating ID tokens.
                  scopes_supported:
                    type: array
                    items:
                      type: string
                  response_types_supported:
                    type: array
                    items:
                      type: string
      security: []

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.