<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Build an OAuth2 Authorization Server · At Least Once</title><description>Fourteen parts, from an empty Spring Boot project to a production-oriented OAuth 2.1-style and OpenID Connect authorization server: PKCE, JWT, refresh rotation, PostgreSQL, user and client administration, revocation, Docker and CI.</description><link>https://blog.subashsdhami.com.np/</link><language>en</language><item><title>Part 0: The plan</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/00-the-plan/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/00-the-plan/</guid><description>What we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oauth2</category><category>oidc</category><category>spring-boot</category></item><item><title>Part 1: The mental model</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/01-the-mental-model/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/01-the-mental-model/</guid><description>OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oauth2</category><category>oidc</category><category>pkce</category><category>jwt</category></item><item><title>Part 2: A server that starts</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/02-a-server-that-starts/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/02-a-server-that-starts/</guid><description>Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>spring-boot</category><category>spring-security</category><category>oauth2</category><category>oidc</category></item><item><title>Part 3: Authorization Code and PKCE, by hand</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/03-authorization-code-and-pkce-by-hand/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/03-authorization-code-and-pkce-by-hand/</guid><description>Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oauth2</category><category>pkce</category><category>jwt</category></item><item><title>Part 4: State that survives a restart</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/04-state-that-survives-a-restart/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/04-state-that-survives-a-restart/</guid><description>Move registered clients, authorizations and consent into PostgreSQL, with Flyway owning the schema.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>postgresql</category><category>flyway</category><category>spring-boot</category></item><item><title>Part 5: Users in the database</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/05-users-in-the-database/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/05-users-in-the-database/</guid><description>Replace the in-memory user with JPA entities, roles, and a database-backed UserDetailsService that accepts username or email.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>spring-security</category><category>jpa</category><category>postgresql</category></item><item><title>Part 6: Registration, errors and dev data</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/06-registration-errors-and-dev-data/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/06-registration-errors-and-dev-data/</guid><description>A registration API with validation, one consistent error format, and demo credentials that only exist in the dev profile.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>spring-boot</category><category>validation</category><category>api-design</category></item><item><title>Part 7: Managing clients and scopes</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/07-managing-clients-and-scopes/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/07-managing-clients-and-scopes/</guid><description>ADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>spring-security</category><category>oauth2</category><category>api-design</category></item><item><title>Part 8: Real tests and stable keys</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/08-real-tests-and-stable-keys/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/08-real-tests-and-stable-keys/</guid><description>Integration tests against real PostgreSQL with Testcontainers, and RSA signing keys that survive a restart.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>testing</category><category>testcontainers</category><category>jwt</category></item><item><title>Part 9: Accounts, passwords and lockout</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/09-accounts-passwords-and-lockout/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/09-accounts-passwords-and-lockout/</guid><description>User administration, self-service and admin password changes, and a temporary lockout after repeated failed logins.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>spring-security</category><category>security</category><category>api-design</category></item><item><title>Part 10: ID tokens and UserInfo</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/10-id-tokens-and-userinfo/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/10-id-tokens-and-userinfo/</guid><description>Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oidc</category><category>jwt</category><category>spring-security</category></item><item><title>Part 11: Revoking a JWT</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/11-revoking-a-jwt/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/11-revoking-a-jwt/</guid><description>Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oauth2</category><category>jwt</category><category>security</category></item><item><title>Part 12: Hardening for production</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/12-hardening-for-production/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/12-hardening-for-production/</guid><description>Externalised issuer and CORS, health probes, and a persistent security audit trail.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>security</category><category>spring-boot</category><category>devops</category></item><item><title>Part 13: Docker, CI and v1.0</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/13-docker-ci-and-v1/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/13-docker-ci-and-v1/</guid><description>A non-root container image, keys mounted at runtime, CI against real PostgreSQL, and a clean v1.0.0 release.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>docker</category><category>ci</category><category>devops</category></item><item><title>Part 14: References</title><link>https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/14-references/</link><guid isPermaLink="true">https://blog.subashsdhami.com.np/series/build-oauth2-authorization-server/14-references/</guid><description>Every specification and document the series relies on, grouped by subject.</description><pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate><category>oauth2</category><category>oidc</category><category>references</category></item></channel></rss>