Protocols & Flows
- Standards‑compliant OpenID Connect 1.0 and OAuth 2.0 for modern client and API architectures
- Authorization Code with PKCE, Client Credentials, Device Authorization, and Token Exchange flows
- security baseline: exact redirect matching, issuer validation, no password grant, and refresh-token replay protection