SignInProvider

A request or response body; the type column links to the schemas it refers to.

SignInProvider

FieldTypeRequiredDescription
idstring (uuid)yes—
slugstringyes—
display_namestringyes

Label shown on the sign-in picker.

issuer_urlstringyes—
client_idstringyes—
enabledbooleanyes

Disabled providers keep their identities but accept no sign-ins or tokens.

client_auth_methodstringyes

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | "none"

client_secret_envstring | nullyes

NAME of the env var holding the client secret; the secret itself never leaves the environment.

client_private_key_envstring | nullyes

NAME of the env var holding the PKCS#8 private key, for private_key_jwt.

client_assertion_algorithmstring | nullyes—
client_key_idstring | nullyes—
audiencestring | nullyes

Expected `aud` of incoming access tokens; null skips the audience check.

request_resourcebooleanyes

Send `audience` as the RFC 8707 `resource` parameter on the sign-in and refresh grants, so the tokens the browser holds carry that audience.

introspection_client_idstring | nullyes

Identity tokens are introspected as, when it differs from the login client — an API server validating the tokens minted for it. Null introspects as the login client.

introspection_auth_methodstring | nullyes

one of "client_secret_basic" | "client_secret_post" | "client_secret_jwt" | "private_key_jwt" | null

introspection_client_secret_envstring | nullyes

NAME of the env var holding the introspection identity's client secret.

introspection_private_key_envstring | nullyes

NAME of the env var holding the introspection identity's PKCS#8 private key, for private_key_jwt.

introspection_client_assertion_algorithmstring | nullyes—
introspection_client_key_idstring | nullyes—
login_scopestringyes—
access_token_algorithmsarray of stringyes

Accepted JWS algorithms for incoming access tokens; empty means the defaults.

email_verification_strictnessstringyes

How the provider's `email_verified` claim gates claiming a pending email link at sign-in: `lenient` links regardless, `reject_unverified` links unless the claim is explicitly false, `require_verified` links only when it is explicitly true.

one of "lenient" | "reject_unverified" | "require_verified"

created_atstring (date-time)yes—
updated_atstring (date-time)yes—
jsonExample
{
  "id": "1b671a64-40d5-491e-99b0-da01ff1f3341",
  "slug": "acme-sso",
  "display_name": "Acme SSO",
  "issuer_url": "https://auth.acme.com",
  "client_id": "string",
  "enabled": true,
  "client_auth_method": "client_secret_basic",
  "client_secret_env": "OIDC_ACME_CLIENT_SECRET",
  "client_private_key_env": "string",
  "client_assertion_algorithm": "string",
  "client_key_id": "string",
  "audience": "string",
  "request_resource": true,
  "introspection_client_id": "string",
  "introspection_auth_method": "client_secret_basic",
  "introspection_client_secret_env": "string",
  "introspection_private_key_env": "string",
  "introspection_client_assertion_algorithm": "string",
  "introspection_client_key_id": "string",
  "login_scope": "openid profile email",
  "access_token_algorithms": [
    "RS256"
  ],
  "email_verification_strictness": "reject_unverified",
  "created_at": "2026-01-01T00:00:00.000Z",
  "updated_at": "2026-01-01T00:00:00.000Z"
}