5 min
A server that starts
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
- spring-boot
- spring-security
5 posts.
Spring Authorization Server on port 9000 with OIDC, a development client and user, token policy, and discovery and JWKS endpoints.
Scope-aware identity claims in the ID token and the UserInfo endpoint, and a real OIDC flow to prove them.
Every specification and document the series relies on, grouped by subject.
OAuth roles, the Authorization Code flow, PKCE, the three kinds of token, and JWT signing, before any code.
What we are building, what OAuth and OpenID Connect each answer, and what this series deliberately leaves out.