Skip to content

basalt / auth/src / discoverOidcProvider

Function: discoverOidcProvider() ​

> discoverOidcProvider(config): Promise<OAuthProvider>

Defined in: auth/src/oauth.ts:253

Builds an oidcProvider by fetching the IdP's OIDC discovery document (${issuer}/.well-known/openid-configuration). Await it at startup.

Per OpenID Connect Discovery §4.3 the document's issuer must equal the configured one (trailing slashes aside), and every endpoint must be https: (plain http: only to a loopback host), or discovery fails.

Parameters ​

config ​

allowAnyEmailDomain? ​

true

See OAuthProvider.allowAnyEmailDomain.

allowedEmailDomains? ​

string[]

See OAuthProvider.allowedEmailDomains.

clientId ​

string

clientSecret ​

string

fetch? ​

(input, init?) => Promise<Response>

issuer ​

string

The IdP issuer URL, e.g. https://acme.okta.com or https://login.microsoftonline.com/<tenant>/v2.0.

name? ​

string

scopes? ​

string[]

timeoutMs? ​

number

Timeout for the discovery request, ms. Default 10 s.

Returns ​

Promise&lt;OAuthProvider&gt;

Released under the MIT License.