Configure Applications with OIDC Discovery
OpenID Connect (OIDC) Discovery documents contain metadata about the identity provider (IdP). Adding discovery to your SDK to point your application to the ./wellknown
endpoint to consume information about your IdP could help configure your integration with the IdP.
Integrating OIDC discovery into your SDK provides:
Exposed endpoints of the IdP
Standard OIDC supported claims and scope (this excludes custom claims and scopes defined in your tenant)
Features supported by the IdP
You can configure applications with the OpenID Connect (OIDC) discovery documents found here: https://{yourDomain}/.well-known/openid-configuration
Sample response
"issuer": "https://{yourDomain}",
"authorization_endpoint": "https://{yourDomain}",
"token_endpoint": "https://{yourDomain}",
"device_authorization_endpoint": "https://{yourDomain}",
"userinfo_endpoint": "https://{yourDomain}",
"mfa_challenge_endpoint": "https://{yourDomain}",
"jwks_uri": "https://{yourDomain}",
"registration_endpoint": "https://{yourDomain}",
"revocation_endpoint": "https://{yourDomain}",
"scopes_supported": [
"response_types_supported": [
"code token",
"code id_token",
"token id_token",
"code token id_token"
"code_challenge_methods_supported": [
"response_modes_supported": [
"subject_types_supported": [
"id_token_signing_alg_values_supported": [
"token_endpoint_auth_methods_supported": [
"claims_supported": [
"request_uri_parameter_supported": false,
"request_parameter_supported": false,
"token_endpoint_auth_signing_alg_values_supported": [
Sample implementation
For example, this is how to configure OIDC middleware for Katana v3 (OWIN):
Install the nuget package: Microsoft.Owin.Security.OpenIdConnect (v3.x.x)
Go to
and replace your implementation with the following:codeblockOld.header.login.configureSnippetapp.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = CookieAuthenticationDefaults.AuthenticationType }); app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions { Authority = "https://{yourDomain}/", ClientId = "{yourClientId}", SignInAsAuthenticationType = CookieAuthenticationDefaults.AuthenticationType, ResponseType = "token", Notifications = new OpenIdConnectAuthenticationNotifications { // OPTIONAL: you can read/modify the claims that are populated based on the JWT SecurityTokenValidated = context => { // add Auth0 Access Token as claim var accessToken = context.ProtocolMessage.AccessToken; if (!string.IsNullOrEmpty(accessToken)) { context.AuthenticationTicket.Identity.AddClaim(new Claim("access_token", accessToken)); } return Task.FromResult(0); } } });
RSA algorithm for JWTs
The OIDC middleware does not support JWTs signed with symmetric keys. Make sure you configure your app to use the RSA algorithm using public/private keys.
Go to Dashboard > Settings.
Scroll down to Advanced Settings.
Under the OAuth tab, set
as Json Web Token(JWT) Signature Algorithm and click Save.
With this setting, Auth0 will issue JWTs signed with your private signing key. Your app will verify them with your public signing key.