{"_id":"@dextersjab/openid-client","_rev":"5-fb1ab9da331d4e8cba5eef2a732e057f","time":{"created":"2022-11-02T17:45:46.599Z","5.1.1-0.2":"2022-10-10T16:09:12.594Z","modified":"2022-12-12T07:54:14.109Z","5.1.1-0.3":"2022-10-10T17:42:30.663Z","0.1.1":"2022-11-02T17:45:46.888Z","0.1.2":"2022-11-30T11:29:05.373Z","0.1.4":"2022-12-12T07:54:14.028Z"},"name":"@dextersjab/openid-client","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.1":{"name":"@dextersjab/openid-client","publishConfig":{"registry":"https://registry.npmjs.org"},"version":"0.1.1","description":"OpenID Connect Relying Party (RP, Client) implementation for Node.js runtime, supports passportjs","keywords":["auth","authentication","basic","certified","client","connect","dynamic","electron","hybrid","identity","implicit","oauth","oauth2","oidc","openid","passport","relying party","strategy"],"homepage":"https://github.com/panva/node-openid-client","repository":{"type":"git","url":"https://github.com/dextersjab/node-openid-client"},"license":"MIT","author":{"name":"Dexter Awoyemi"},"exports":{"types":"./types/index.d.ts","import":"./lib/index.mjs","require":"./lib/index.js"},"main":"./lib/index.js","types":"./types/index.d.ts","scripts":{"coverage":"nyc mocha test/**/*.test.js","prettier":"npx prettier --loglevel silent --write ./lib ./test ./certification ./types","test":"mocha test/**/*.test.js"},"nyc":{"reporter":["lcov","text-summary"]},"dependencies":{"jose":"^4.1.4","jsonwebtoken":"^8.5.1","lru-cache":"^6.0.0","object-hash":"^2.0.1","oidc-token-hash":"^5.0.1"},"devDependencies":{"@types/node":"^16.11.5","@types/passport":"^1.0.7","base64url":"^3.0.1","chai":"^4.2.0","jose2":"npm:jose@^2.0.5","mocha":"^8.2.0","nock":"^13.0.2","nyc":"^15.1.0","prettier":"^2.4.1","readable-mock-req":"^0.2.2","sinon":"^9.2.0","timekeeper":"^2.2.0"},"standard-version":{"scripts":{"postchangelog":"sed -i '' -e 's/### \\[/## [/g' CHANGELOG.md"},"types":[{"type":"feat","section":"Features"},{"type":"fix","section":"Fixes"},{"type":"chore","hidden":true},{"type":"docs","hidden":true},{"type":"style","hidden":true},{"type":"refactor","section":"Refactor","hidden":false},{"type":"perf","section":"Performance","hidden":false},{"type":"test","hidden":true}]},"licenseText":"The MIT License (MIT)\n\nCopyright (c) 2016 Filip Skokan\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@dextersjab/openid-client@0.1.1","dist":{"shasum":"06832cf75eb995883692d1d673116940e6ac5d66","integrity":"sha512-aChmWTPUE5jNu+bjl3vnOUNRHwBDbZsA9c0aJAaAMXMfvH8z5JRPurEM1inxK+O3IJjhYsk5UNf8LfcszKczUA==","tarball":"https://registry.npmjs.org/@dextersjab/openid-client/-/openid-client-0.1.1.tgz","fileCount":38,"unpackedSize":190274,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDXxdHnCNZ3IvO+UIurOthmf6a+k2p66EOcAt5fd3ffGAiA8SRjuOij1n9GJ8G3q0GzYDkiSS9u/4cpoo4YFBBAC6g=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjYqzKACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJ2Q/9HDbcrfOHkHqPnPVkl5MO3sEL/fGaEbLABWleD1gWlnEj9PJ8\r\nSgazR0nARnozpKgsq5rqVB0SxiH9/5mHFO7SmeW52pjIrjLUSBBE8I3KHTEg\r\nhDuoCtuyfmHuZqNkP44SILxkwHxU4QJs/jeeN81szMg5jZvYBLE0PSeDCiVo\r\n6ww7OD3kEiYHop2GSLo+XCRkFwDiPB6jdiR+1ftlMX/XrCBHkiZvNVKof3jl\r\nTNddPr1BO38x44D8bgXNh8Q2OSjy9e5lvOsl9xBhVlYFi2G7w65RvgwsOFp3\r\n8d+IxR4j/qbzOXpRLC/5i5V518qOaumodqpupGdBMuVy6c9rkp+pOHSSknaG\r\n+IHup6copXQSsBj8q+iiP36h4O4KTI+8fLrZ9NhMLPB3MKMvr0q1zzFssJNm\r\nxIpKWqdMl4jGTVIHyQWrKcn+hGfPINrtbHTPgBYXA2MeVZbWPmtV/RYDantM\r\n15s+LVWRLYc9ZkaUg3F02g4TwaG6JXBxwLpkdVFnjLoV2YYn8lwPKBYDDh6d\r\nuBEL5v5EOqLM5j6RqU620m1jqvub5ECQMD8xeLYMP+6TAiU/OojqkrnPKWBp\r\nWSpxcZS/+NRZVqauQDl5SDjds2Zm7qX2vpbcwe54/cF/B2BPjeVprCc9N66+\r\nW5a7JGcv6/Ny51/NBevwkNBWjJ8qTqRidlM=\r\n=Eps7\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"},"directories":{},"maintainers":[{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/openid-client_0.1.1_1667411146650_0.6522149662496965"},"_hasShrinkwrap":false},"0.1.2":{"name":"@dextersjab/openid-client","publishConfig":{"registry":"https://registry.npmjs.org"},"version":"0.1.2","description":"OpenID Connect Relying Party (RP, Client) implementation for Node.js runtime, supports passportjs","keywords":["auth","authentication","basic","certified","client","connect","dynamic","electron","hybrid","identity","implicit","oauth","oauth2","oidc","openid","passport","relying party","strategy"],"homepage":"https://github.com/panva/node-openid-client","repository":{"type":"git","url":"https://github.com/dextersjab/node-openid-client"},"license":"MIT","author":{"name":"Dexter Awoyemi"},"exports":{"types":"./types/index.d.ts","import":"./lib/index.mjs","require":"./lib/index.js"},"main":"./lib/index.js","types":"./types/index.d.ts","scripts":{"coverage":"nyc mocha test/**/*.test.js","prettier":"npx prettier --loglevel silent --write ./lib ./test ./certification ./types","test":"mocha test/**/*.test.js"},"nyc":{"reporter":["lcov","text-summary"]},"dependencies":{"jose":"^4.1.4","jsonwebtoken":"^8.5.1","lru-cache":"^6.0.0","object-hash":"^2.0.1","oidc-token-hash":"^5.0.1"},"devDependencies":{"@types/node":"^16.11.5","@types/passport":"^1.0.7","base64url":"^3.0.1","chai":"^4.2.0","jose2":"npm:jose@^2.0.5","mocha":"^8.2.0","nock":"^13.0.2","nyc":"^15.1.0","prettier":"^2.4.1","readable-mock-req":"^0.2.2","sinon":"^9.2.0","timekeeper":"^2.2.0"},"standard-version":{"scripts":{"postchangelog":"sed -i '' -e 's/### \\[/## [/g' CHANGELOG.md"},"types":[{"type":"feat","section":"Features"},{"type":"fix","section":"Fixes"},{"type":"chore","hidden":true},{"type":"docs","hidden":true},{"type":"style","hidden":true},{"type":"refactor","section":"Refactor","hidden":false},{"type":"perf","section":"Performance","hidden":false},{"type":"test","hidden":true}]},"licenseText":"The MIT License (MIT)\n\nCopyright (c) 2016 Filip Skokan\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@dextersjab/openid-client@0.1.2","dist":{"shasum":"ee6dc1b736cb547b939a68e49e0a447604fec550","integrity":"sha512-0OtiqT5O4QzrUg03uDHuOMpspPqskoXU1iwmm++2vU9FP5vG9JarrhMw8g98U4/I+CdgpfNlEQ8pwUHAMIzDiw==","tarball":"https://registry.npmjs.org/@dextersjab/openid-client/-/openid-client-0.1.2.tgz","fileCount":38,"unpackedSize":191407,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCZpjn3XF/MV8JO6eWjeJCbtYyjz3xxZt1ZxD7BbOakSQIgb1FcnWVeE1EN2y5pXMoLPAMlM6dJo6/UhKRhL2irSGk="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjhz6BACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrLqg/+Pmfxn/URkBUcJNjJ7jxs2L49XHd4nRuZax+0dkrc6JPWCw8P\r\nT6UXTb6pxlT+DfBGQpkdn22QY/e1/pPO6emWljJkMIZV1+vicVaB/zCqVrDQ\r\nJrd43M2wtuQoJzEYEXoquDwid/9WAcS0mFyiRlYdbr+idoEhucQZdt4L9fAC\r\nKnQYt2n8I3kLd3ww7wpyUM7o6o/o0R47c+6erlvhwD3hnYZJHT75LN1Mq2D/\r\nVp/8AFZTmts73un2QH6VAsA5P8QqWK1KSCFXlX2x6uXbilFzRR21/ZYH6nL6\r\nHsDoPdepnG4IqKd3kx3YjZc8nemriXGURfQIM4imfnMwXlea1HnFrcToRNRu\r\nXOnTKZUd0vg/rTnKuN+1zdDhh+4bHyEvNDC+9HrXEc0OuyZJXeEjucHGizug\r\n0Ol5/tQ2yb9CS9IWs7awQ2ztB05KjIJdMjpslPrJPWEHcmv0MFyPNaUhKTx3\r\nfRJvPC8iivx4VJ+aY2MMCGTwNAULy6ELa1dkqHsP7gHeOWXghW1gHgZBteqN\r\nMR8G8JhtslJeCalcyr+Jy5kCRuppikmBG5JIJTeTxFeMmsaA3aPf2cY7CPXF\r\n89lICcmtRESDVnQssnAl+Hq3AhC1cD5ia7N+u+SR+bbiuWqVLuVgCDTXALhU\r\nX9hciTHhMYX2WDrN3tW32alcEm6QR/LKrEs=\r\n=aNt0\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"},"directories":{},"maintainers":[{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/openid-client_0.1.2_1669807745216_0.6501648590249247"},"_hasShrinkwrap":false},"0.1.4":{"name":"@dextersjab/openid-client","publishConfig":{"registry":"https://registry.npmjs.org"},"version":"0.1.4","description":"OpenID Connect Relying Party (RP, Client) implementation for Node.js runtime, supports passportjs","keywords":["auth","authentication","basic","certified","client","connect","dynamic","electron","hybrid","identity","implicit","oauth","oauth2","oidc","openid","passport","relying party","strategy"],"homepage":"https://github.com/panva/node-openid-client","repository":{"type":"git","url":"https://github.com/dextersjab/node-openid-client"},"license":"MIT","author":{"name":"Dexter Awoyemi"},"exports":{"types":"./types/index.d.ts","import":"./lib/index.mjs","require":"./lib/index.js"},"main":"./lib/index.js","types":"./types/index.d.ts","scripts":{"coverage":"nyc mocha test/**/*.test.js","prettier":"npx prettier --loglevel silent --write ./lib ./test ./certification ./types","test":"mocha test/**/*.test.js"},"nyc":{"reporter":["lcov","text-summary"]},"dependencies":{"jose":"^4.1.4","jsonwebtoken":"^8.5.1","lru-cache":"^6.0.0","object-hash":"^2.0.1","oidc-token-hash":"^5.0.1"},"devDependencies":{"@types/node":"^16.11.5","@types/passport":"^1.0.7","base64url":"^3.0.1","chai":"^4.2.0","jose2":"npm:jose@^2.0.5","mocha":"^8.2.0","nock":"^13.0.2","nyc":"^15.1.0","prettier":"^2.4.1","readable-mock-req":"^0.2.2","sinon":"^9.2.0","timekeeper":"^2.2.0"},"standard-version":{"scripts":{"postchangelog":"sed -i '' -e 's/### \\[/## [/g' CHANGELOG.md"},"types":[{"type":"feat","section":"Features"},{"type":"fix","section":"Fixes"},{"type":"chore","hidden":true},{"type":"docs","hidden":true},{"type":"style","hidden":true},{"type":"refactor","section":"Refactor","hidden":false},{"type":"perf","section":"Performance","hidden":false},{"type":"test","hidden":true}]},"licenseText":"The MIT License (MIT)\n\nCopyright (c) 2016 Filip Skokan\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","_id":"@dextersjab/openid-client@0.1.4","dist":{"shasum":"5f6c9174510e5191884059d57c0ecea970a58fc7","integrity":"sha512-QZzwJuEi1ur0ey6qepXy0Z4ReyYcz0g1rhIJgskANsVOy5tgWLkTxAeK7eA69hP3KKYQFnO73dfd0kWcULFemw==","tarball":"https://registry.npmjs.org/@dextersjab/openid-client/-/openid-client-0.1.4.tgz","fileCount":38,"unpackedSize":191307,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEzVp+ECl8kCahUSRUJCpPbDJXZpS5+NgaZyY7vVtXxxAiBW21BqtDK5PhJ1da18gibd2FWNOT2DbbmOtN4kBB4rgg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjlt4mACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqm0Q/9FnE0l/907GIDg2LsBL9vOVgfDP7Y/Xf6BJIGpTyWbCSnieVd\r\nDkZIU65t1CfWMM086uPEW0+6bQy5tvfES4JXC15ZxnVnNhbzAg+Uf67OePmz\r\n/FCU/u0EgG77sf1gPLClT7ETmZfB/HMQY68Fr5pvNfTXtHmCBB4Hsnk1CB9W\r\nEExdhF4d2AewizhFr8ucI6jaXzsKswBWsSm2BYuFJgNuNcGbNuE9LKBxWwNi\r\nYZmLawi9RJdQems8fhAq1/tZitMjzdRlIlSRQRitMhZa490r400/0B++R4hf\r\nAVNGoaSPFGLSnRzo7Eb7rAW/x52ALl1lSBkS6p0Qqy0XxmQDvBuwrWFAjfpo\r\nAQAxn7e6YtOA2NYojzac9Cdn/lWX7KH2PYypxEzy+Fk8XB6gPAtzF4xP0wfy\r\nLF+93uboW1ATSG0Ei3wpvbyfbbFkbu3y9t9hLMDgnU39oMBlkyXhfpiKF7u5\r\n0lXWxsL96f3Wrt+St8IFD3woYkBuLH5t3H14iA0uNFu9oupGPKhCWmHRZER1\r\naTYaGT7L+eA6uWIZXn93RUWtDNAfjWtSoho+LHnCN4o2GmUeKW9r8t7d2ZF+\r\nwDxFBfpf5l5Te5w/lmwod4y721vsrjWbZieBvwLflkOkzwDPFpv2IDrF/3Ks\r\nl8ltNtC553NQjsMnxriIVV3PS8cOB5xcJDI=\r\n=2om9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"},"directories":{},"maintainers":[{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/openid-client_0.1.4_1670831653868_0.021547160556692146"},"_hasShrinkwrap":false}},"maintainers":[{"name":"dextersjab","email":"dexter.awoyemi@gmail.com"}],"description":"OpenID Connect Relying Party (RP, Client) implementation for Node.js runtime, supports passportjs","homepage":"https://github.com/panva/node-openid-client","keywords":["auth","authentication","basic","certified","client","connect","dynamic","electron","hybrid","identity","implicit","oauth","oauth2","oidc","openid","passport","relying party","strategy"],"repository":{"type":"git","url":"https://github.com/dextersjab/node-openid-client"},"author":{"name":"Dexter Awoyemi"},"license":"MIT","readme":"# Modified version of openid-client\n\nThis library is forked from [panva's openid-client](https://github.com/panva/node-openid-client)\nto accommodate the [Open Banking UK (OBIE)'s implementation of the\nOIDC dynamic client registration](https://openbankinguk.github.io/dcr-docs-pub/v3.3/dynamic-client-registration.html).\n\nThe primary difference is that this library allows registration payloads to be\nsubmitted as a JWS. So it's not strictly OIDC-compliant, whereas openid-client is.\n\nI'm not sure at this stage whether OIDF will extend FAPI to allow this or\nwhether OBIE will transition to full FAPI compliance.\n\nAlso, Dynamic Client Registration has been extended to support registration deletion\n(from [RFC 7592](https://datatracker.ietf.org/doc/html/rfc7592)), used for example by\n[Open Banking UK](https://openbankinguk.github.io/dcr-docs-pub/v3.3/dynamic-client-registration.html).\n\n# openid-client\n\nopenid-client is a server side [OpenID][openid-connect] Relying Party (RP, Client) implementation for\nNode.js runtime, supports [passport][passport-url].\n\n## Implemented specs & features\n\nThe following client/RP features from OpenID Connect/OAuth2.0 specifications are implemented by\nopenid-client.\n\n- [OpenID Connect Core 1.0][feature-core]\n  - Authorization Callback\n    - Authorization Code Flow\n    - Implicit Flow\n    - Hybrid Flow\n  - UserInfo Request\n  - Offline Access / Refresh Token Grant\n  - Client Credentials Grant\n  - Client Authentication\n    - none\n    - client_secret_basic\n    - client_secret_post\n    - client_secret_jwt\n    - private_key_jwt\n  - Consuming Self-Issued OpenID Provider ID Token response\n- [OpenID Connect Discovery 1.0][feature-discovery]\n  - Discovery of OpenID Provider (Issuer) Metadata\n  - Discovery of OpenID Provider (Issuer) Metadata via user provided inputs (via [webfinger][documentation-webfinger])\n- [OpenID Connect Dynamic Client Registration 1.0][feature-registration]\n  - Dynamic Client Registration request\n  - Client initialization via registration client uri\n- [RFC7009 - OAuth 2.0 Token revocation][feature-revocation]\n  - Client Authenticated request to token revocation\n- [RFC7662 - OAuth 2.0 Token introspection][feature-introspection]\n  - Client Authenticated request to token introspection\n- [RFC8628 - OAuth 2.0 Device Authorization Grant (Device Flow)][feature-device-flow]\n- [RFC8705 - OAuth 2.0 Mutual TLS Client Authentication and Certificate-Bound Access Tokens][feature-mtls]\n  - Mutual TLS Client Certificate-Bound Access Tokens\n  - Metadata for Mutual TLS Endpoint Aliases\n  - Client Authentication\n    - tls_client_auth\n    - self_signed_tls_client_auth\n- [RFC9101 - OAuth 2.0 JWT-Secured Authorization Request (JAR)][feature-jar]\n- [RFC9126 - OAuth 2.0 Pushed Authorization Requests (PAR)][feature-par]\n- [OpenID Connect RP-Initiated Logout 1.0 - draft 01][feature-rp-logout]\n- [Financial-grade API Security Profile 1.0 - Part 2: Advanced (FAPI)][feature-fapi]\n- [JWT Secured Authorization Response Mode for OAuth 2.0 (JARM) - ID1][feature-jarm]\n- [OAuth 2.0 Demonstration of Proof-of-Possession at the Application Layer (DPoP) - draft 04][feature-dpop]\n- [OAuth 2.0 Authorization Server Issuer Identification - draft-04][feature-iss]\n\nUpdates to draft specifications (DPoP, JARM, etc) are released as MINOR library versions,\nif you utilize these specification implementations consider using the tilde `~` operator in your\npackage.json since breaking changes may be introduced as part of these version updates. \n\n## Certification\n[<img width=\"184\" height=\"96\" align=\"right\" src=\"https://cdn.jsdelivr.net/gh/panva/node-openid-client@38cf016b0837e6d4116de3780b28d222d5780bc9/OpenID_Certified.png\" alt=\"OpenID Certification\">][openid-certified-link]  \nFilip Skokan has [certified][openid-certified-link] that [openid-client][npm-url]\nconforms to the following profiles of the OpenID Connect™ protocol\n\n- Basic, Implicit, Hybrid, Config, Dynamic, and Form Post RP\n- FAPI 1.0 Advanced RP\n\n## Sponsor\n\n[<img height=\"65\" align=\"left\" src=\"https://cdn.auth0.com/blog/github-sponsorships/brand-evolution-logo-Auth0-horizontal-Indigo.png\" alt=\"auth0-logo\">][sponsor-auth0] If you want to quickly add OpenID Connect authentication to Node.js apps, feel free to check out Auth0's Node.js SDK and free plan. [Create an Auth0 account; it's free!][sponsor-auth0]<br><br>\n\n## Support\n\nIf you or your business use openid-client, please consider becoming a [sponsor][support-sponsor] so I can continue maintaining it and adding new features carefree.\n\n\n## Documentation\n\nThe library exposes what are essentially steps necessary to be done by a relying party consuming\nOpenID Connect Authorization Server responses or wrappers around requests to its endpoints. Aside\nfrom a generic OpenID Connect [passport][passport-url] strategy it does not expose any framework\nspecific middlewares. Those can however be built using the exposed API, one such example is [express-openid-connect][]\n\n- [openid-client API Documentation][documentation]\n  - [Issuer][documentation-issuer]\n  - [Client][documentation-client]\n  - [Customizing][documentation-customizing]\n  - [TokenSet][documentation-tokenset]\n  - [Strategy][documentation-strategy]\n  - [generators][documentation-generators]\n  - [errors][documentation-errors]\n\n## Install\n\nNode.js LTS releases Codename Erbium (starting with ^12.19.0) and newer LTS releases are supported.\n\n```console\nnpm install @dextersjab/openid-client\n```\n\n## Quick start\n\nDiscover an Issuer configuration using its published .well-known endpoints\n```js\nimport { Issuer } from 'openid-client';\n\nconst googleIssuer = await Issuer.discover('https://accounts.google.com');\nconsole.log('Discovered issuer %s %O', googleIssuer.issuer, googleIssuer.metadata);\n```\n\n### Authorization Code Flow\n\nAuthorization Code flow is for obtaining Access Tokens (and optionally Refresh Tokens) to use with\nthird party APIs securely as well as Refresh Tokens. In this quick start your application also uses\nPKCE instead of `state` parameter for CSRF protection.\n\nCreate a Client instance for that issuer's authorization server intended for Authorization Code\nflow.\n\n**See the [documentation][] for full API details.**\n\n```js\nconst client = new googleIssuer.Client({\n  client_id: 'zELcpfANLqY7Oqas',\n  client_secret: 'TQV5U29k1gHibH5bx1layBo0OSAvAbRT3UYW3EWrSYBB5swxjVfWUa1BS8lqzxG/0v9wruMcrGadany3',\n  redirect_uris: ['http://localhost:3000/cb'],\n  response_types: ['code'],\n  // id_token_signed_response_alg (default \"RS256\")\n  // token_endpoint_auth_method (default \"client_secret_basic\")\n}); // => Client\n```\n\nWhen you want to have your end-users authorize you need to send them to the issuer's\n`authorization_endpoint`. Consult the web framework of your choice on how to redirect but here's how\nto get the authorization endpoint's URL with parameters already encoded in the query to redirect\nto.\n\n```js\nimport { generators } from 'openid-client';\nconst code_verifier = generators.codeVerifier();\n// store the code_verifier in your framework's session mechanism, if it is a cookie based solution\n// it should be httpOnly (not readable by javascript) and encrypted.\n\nconst code_challenge = generators.codeChallenge(code_verifier);\n\nclient.authorizationUrl({\n  scope: 'openid email profile',\n  resource: 'https://my.api.example.com/resource/32178',\n  code_challenge,\n  code_challenge_method: 'S256',\n});\n```\n\nWhen end-users are redirected back to your `redirect_uri` your application consumes the callback and\npasses in the `code_verifier` to include it in the authorization code grant token exchange.\n```js\nconst params = client.callbackParams(req);\nconst tokenSet = await client.callback('https://client.example.com/callback', params, { code_verifier });\nconsole.log('received and validated tokens %j', tokenSet);\nconsole.log('validated ID Token claims %j', tokenSet.claims());\n```\n\nYou can then call the `userinfo_endpoint`.\n```js\nconst userinfo = await client.userinfo(access_token);\nconsole.log('userinfo %j', userinfo);\n```\n\nAnd later refresh the tokenSet if it had a `refresh_token`.\n```js\nconst tokenSet = await client.refresh(refresh_token);\nconsole.log('refreshed and validated tokens %j', tokenSet);\nconsole.log('refreshed ID Token claims %j', tokenSet.claims());\n```\n\n### Implicit ID Token Flow\n\nImplicit `response_type=id_token` flow is perfect for simply authenticating your end-users, assuming\nthe only job you want done is authenticating the user and then relying on your own session mechanism\nwith no need for accessing any third party APIs with an Access Token from the Authorization Server.\n\nCreate a Client instance for that issuer's authorization server intended for ID Token implicit flow.\n\n**See the [documentation][] for full API details.**\n```js\nconst client = new googleIssuer.Client({\n  client_id: 'zELcpfANLqY7Oqas',\n  redirect_uris: ['http://localhost:3000/cb'],\n  response_types: ['id_token'],\n  // id_token_signed_response_alg (default \"RS256\")\n}); // => Client\n```\n\nWhen you want to have your end-users authorize you need to send them to the issuer's\n`authorization_endpoint`. Consult the web framework of your choice on how to redirect but here's how\nto get the authorization endpoint's URL with parameters already encoded in the query to redirect\nto.\n\n```js\nimport { generators } from 'openid-client';\nconst nonce = generators.nonce();\n// store the nonce in your framework's session mechanism, if it is a cookie based solution\n// it should be httpOnly (not readable by javascript) and encrypted.\n\nclient.authorizationUrl({\n  scope: 'openid email profile',\n  response_mode: 'form_post',\n  nonce,\n});\n```\n\nWhen end-users hit back your `redirect_uri` with a POST (authorization request included `form_post`\nresponse mode) your application consumes the callback and passes the `nonce` in to include it in the\nID Token verification steps.\n```js\n// assumes req.body is populated from your web framework's body parser\nconst params = client.callbackParams(req);\nconst tokenSet = await client.callback('https://client.example.com/callback', params, { nonce });\nconsole.log('received and validated tokens %j', tokenSet);\nconsole.log('validated ID Token claims %j', tokenSet.claims());\n```\n\n### Device Authorization Grant (Device Flow)\n\n[RFC8628 - OAuth 2.0 Device Authorization Grant (Device Flow)](https://tools.ietf.org/html/rfc8628)\nis started by starting a Device Authorization Request.\n\n```js\nconst handle = await client.deviceAuthorization();\nconsole.log('User Code: ', handle.user_code);\nconsole.log('Verification URI: ', handle.verification_uri);\nconsole.log('Verification URI (complete): ', handle.verification_uri_complete);\n```\n\nThe handle represents a Device Authorization Response with the `verification_uri`, `user_code` and\nother defined response properties.\n\nYou will display the instructions to the end-user and have him directed at `verification_uri` or\n`verification_uri_complete`, afterwards you can start polling for the Device Access Token Response.\n```js\nconst tokenSet = await handle.poll();\nconsole.log('received tokens %j', tokenSet);\n```\n\nThis will poll in the defined interval and only resolve with a TokenSet once one is received. This\nwill handle the defined `authorization_pending` and `slow_down` \"soft\" errors and continue polling\nbut upon any other error it will reject. With tokenSet received you can throw away the handle.\n\n## FAQ\n\n#### Semver?\n\n**Yes.** Everything that's either exported in the TypeScript definitions file or\n[documented][documentation] is subject to\n[Semantic Versioning 2.0.0](https://semver.org/spec/v2.0.0.html). The rest is to be considered\nprivate API and is subject to change between any versions.\n\n#### How do I use it outside of Node.js\n\nIt is **only built for Node.js** environments - including openid-client in\nbrowser-environment targeted projects is not supported.\n\n#### How to make the client send client_id and client_secret in the body?\n\nSee [Client Authentication Methods (docs)][documentation-methods].\n\n#### Can I adjust the HTTP timeout?\n\nSee [Customizing (docs)][documentation-customizing].\n\n\n[openid-connect]: https://openid.net/connect/\n[feature-core]: https://openid.net/specs/openid-connect-core-1_0.html\n[feature-discovery]: https://openid.net/specs/openid-connect-discovery-1_0.html\n[feature-registration]: https://openid.net/specs/openid-connect-registration-1_0.html\n[feature-revocation]: https://tools.ietf.org/html/rfc7009\n[feature-introspection]: https://tools.ietf.org/html/rfc7662\n[feature-mtls]: https://tools.ietf.org/html/rfc8705\n[feature-device-flow]: https://tools.ietf.org/html/rfc8628\n[feature-rp-logout]: https://openid.net/specs/openid-connect-rpinitiated-1_0-01.html\n[feature-jarm]: https://openid.net/specs/openid-financial-api-jarm-ID1.html\n[feature-fapi]: https://openid.net/specs/openid-financial-api-part-2-1_0.html\n[feature-dpop]: https://tools.ietf.org/html/draft-ietf-oauth-dpop-04\n[feature-par]: https://www.rfc-editor.org/rfc/rfc9126.html\n[feature-jar]: https://www.rfc-editor.org/rfc/rfc9101.html\n[feature-iss]: https://datatracker.ietf.org/doc/html/draft-ietf-oauth-iss-auth-resp-04\n[openid-certified-link]: https://openid.net/certification/\n[passport-url]: http://passportjs.org\n[npm-url]: https://www.npmjs.com/package/openid-client\n[sponsor-auth0]: https://a0.to/try-auth0\n[support-sponsor]: https://github.com/sponsors/panva\n[documentation]: https://github.com/panva/node-openid-client/blob/master/docs/README.md\n[documentation-issuer]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#issuer\n[documentation-client]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#client\n[documentation-customizing]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#customizing\n[documentation-tokenset]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#tokenset\n[documentation-strategy]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#strategy\n[documentation-errors]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#errors\n[documentation-generators]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#generators\n[documentation-methods]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#client-authentication-methods\n[documentation-webfinger]: https://github.com/panva/node-openid-client/blob/master/docs/README.md#issuerwebfingerinput\n[express-openid-connect]: https://www.npmjs.com/package/express-openid-connect\n","readmeFilename":"README.md"}