A server that starts
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
- spring-boot
- spring-security
7 posts.
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
Run the full browser flow with curl, inspect the tokens, rotate a refresh token, and watch PKCE reject a wrong verifier.
ADMIN-only APIs for OAuth clients and a scope registry, with roles carried in the access token.
Every specification and document the series relies on, grouped by subject.
Token revocation and introspection, and a filter that makes the management APIs reject a revoked JWT immediately.
OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.
What we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out.