Package com.codename1.io.oidc


package com.codename1.io.oidc

OpenID Connect (OIDC) client with PKCE.

OidcClient drives the Authorization Code + PKCE flow against any standards-compliant identity provider (Auth0, Okta, Google, Microsoft Entra, Keycloak, ...). It launches a system browser via SystemBrowser / OidcBrowserNative, exchanges the authorization code for tokens, and persists them through a pluggable TokenStore.

Companion classes (OidcConfiguration, OidcTokens, PkceChallenge, OidcException) carry configuration, results and errors.

  • Class
    Description
    Service-provider interface that SystemBrowser uses to dispatch a sign-in flow through the OS's hardened sign-in surface (ASWebAuthenticationSession on iOS, androidx.browser.customtabs / Credential Manager on Android).
    Modern OpenID Connect / OAuth 2.0 client.
    The subset of an OpenID Connect provider's .well-known/openid-configuration document that OidcClient cares about.
    Fluent builder for OidcConfiguration.
    What an authorization server answers when a device starts the device authorization grant (RFC 8628): the code the user types, where they type it, and how the device waits.
    Thrown for failures during an OpenID Connect / OAuth 2.0 flow driven by OidcClient.
    Sends an OidcClient's access token with the application's requests, and renews it with the refresh token when the service refuses it.
    Told when the user has to sign in again.
    The tokens returned by an OpenID Connect token endpoint, with convenience accessors for the OIDC ID token claims.
    One PKCE pair (RFC 7636).
    A TokenStore that keeps an OidcClient's tokens in the platform's secure storage -- the iOS keychain, the Android keystore, and what each desktop and browser port provides -- instead of the application's ordinary Storage.
    Routes an authorization-code-flow sign-in through the system browser (ASWebAuthenticationSession on iOS, an Android Custom Tab on Android, the user's default browser on JavaSE / Web) and resolves with the final redirect URL once the OS hands it back.
    Pluggable persistence for an OidcClient's tokens.
    The default store.