SignInProvider
A request or response body; the type column links to the schemas it refers to.
SignInProvider
| Field | Type | Required | Description |
|---|---|---|---|
| id | string (uuid) | yes | — |
| slug | string | yes | — |
| display_name | string | yes | Label shown on the sign-in picker. |
| issuer_url | string | yes | — |
| client_id | string | yes | — |
| enabled | boolean | yes | Disabled providers keep their identities but accept no sign-ins or tokens. |
| client_auth_method | string | yes | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none" |
| client_secret_env | string | null | yes | NAME of the env var holding the client secret; the secret itself never leaves the environment. |
| client_private_key_env | string | null | yes | NAME of the env var holding the PKCS#8 private key, for private_key_jwt. |
| client_assertion_algorithm | string | null | yes | — |
| client_key_id | string | null | yes | — |
| audience | string | null | yes | Expected `aud` of incoming access tokens; null skips the audience check. |
| request_resource | boolean | yes | Send `audience` as the RFC 8707 `resource` parameter on the sign-in and refresh grants, so the tokens the browser holds carry that audience. |
| introspection_client_id | string | null | yes | Identity tokens are introspected as, when it differs from the login client — an API server validating the tokens minted for it. Null introspects as the login client. |
| introspection_auth_method | string | null | yes | one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null |
| introspection_client_secret_env | string | null | yes | NAME of the env var holding the introspection identity's client secret. |
| introspection_private_key_env | string | null | yes | NAME of the env var holding the introspection identity's PKCS#8 private key, for private_key_jwt. |
| introspection_client_assertion_algorithm | string | null | yes | — |
| introspection_client_key_id | string | null | yes | — |
| login_scope | string | yes | — |
| access_token_algorithms | array of string | yes | Accepted JWS algorithms for incoming access tokens; empty means the defaults. |
| email_verification_strictness | string | yes | How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true. one of "lenient" | "reject_unverified" | "require_verified" |
| created_at | string (date-time) | yes | — |
| updated_at | string (date-time) | yes | — |
{
"id": "1b671a64-40d5-491e-99b0-da01ff1f3341",
"slug": "acme-sso",
"display_name": "Acme SSO",
"issuer_url": "https://auth.acme.com",
"client_id": "string",
"enabled": true,
"client_auth_method": "client_secret_basic",
"client_secret_env": "OIDC_ACME_CLIENT_SECRET",
"client_private_key_env": "string",
"client_assertion_algorithm": "string",
"client_key_id": "string",
"audience": "string",
"request_resource": true,
"introspection_client_id": "string",
"introspection_auth_method": "client_secret_basic",
"introspection_client_secret_env": "string",
"introspection_private_key_env": "string",
"introspection_client_assertion_algorithm": "string",
"introspection_client_key_id": "string",
"login_scope": "openid profile email",
"access_token_algorithms": [
"RS256"
],
"email_verification_strictness": "reject_unverified",
"created_at": "2026-01-01T00:00:00.000Z",
"updated_at": "2026-01-01T00:00:00.000Z"
}