Build an OAuth2 Authorization Server with Spring Boot

Series

Build an OAuth2 Authorization Server

Fourteen parts, from an empty Spring Boot project to a production-oriented OAuth 2.1-style and OpenID Connect authorization server: PKCE, JWT, refresh rotation, PostgreSQL, user and client administration, revocation, Docker and CI.

  • 15 parts
  • 12 hours total
  • beginner to intermediate to advanced
  • Java 25 · Spring Boot 4 · Spring Security · PostgreSQL

Foundations

2 parts
  1. The planWhat we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out. about 10 minutes, reading only beginner
  2. The mental modelOAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code. about 25 minutes, reading only beginner

A working server

2 parts
  1. A server that startsSpring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints. about 45 minutes intermediate
  2. Authorization Code and PKCE, by handRun the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier. about 40 minutes intermediate

Persistence and identity

3 parts
  1. State that survives a restartMove registered clients, authorizations and consent into PostgreSQL, with Flyway owning the schema. about 60 minutes intermediate
  2. Users in the databaseReplace the in-memory user with JPA entities, roles, and a database-backed UserDetailsService that accepts username or email. about 60 minutes intermediate
  3. Registration, errors and dev dataA registration API with validation, one consistent error format, and demo credentials that only exist in the dev profile. about 45 minutes intermediate

Administration and security

3 parts
  1. Managing clients and scopesADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token. about 90 minutes advanced
  2. Real tests and stable keysIntegration tests against real PostgreSQL with Testcontainers, and RSA signing keys that survive a restart. about 60 minutes advanced
  3. Accounts, passwords and lockoutUser administration, self-service and admin password changes, and a temporary lockout after repeated failed logins. about 75 minutes advanced

Completing the protocol

2 parts
  1. ID tokens and UserInfoScope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them. about 45 minutes advanced
  2. Revoking a JWTToken revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately. about 45 minutes advanced

Production

2 parts
  1. Hardening for productionExternalised issuer and CORS, health probes, and a persistent security audit trail. about 60 minutes advanced
  2. Docker, CI and v1.0A non-root container image, keys mounted at runtime, CI against real PostgreSQL, and a clean v1.0.0 release. about 60 minutes advanced

Reference

1 part
  1. ReferencesEvery specification and document the series relies on, grouped by subject. a reference, not a read beginner