@sometic/auth-oidc
v1.0.10
Published
OIDC Authorization Code + PKCE auth provider for Sometic.
Maintainers
Readme
@sometic/auth-oidc
OIDC Authorization Code + PKCE provider for @sometic/auth.
createOidcAuthProvider implements browser-friendly OpenID Connect: discovery or explicit endpoints, PKCE challenge storage, startOAuth / completeOAuth, token refresh, and optional userinfo mapping. No proprietary IdP SDK is required; it uses fetch and Web Crypto.
Use this when your identity provider speaks OIDC (Auth0, Keycloak, Cognito hosted UI, Okta, etc.) and you want Sometic session orchestration without embedding vendor clients. Redirect URI matching is exact by default; PKCE is S256. When sessionStorage exists, the verifier is persisted there across full-page redirects.
Standout options: clientId, redirectUri, issuer discovery, explicit endpoints, injectable fetcher / store, and scopes (default openid profile email). Capabilities focus on OAuth, refresh, session, and sign-out rather than password sign-in.
Works with @sometic/auth, @sometic/http for API calls after login, and @sometic/core. Docs: introduction and auth providers.
Install
pnpm add @sometic/auth-oidc @sometic/authnpm install @sometic/auth-oidc @sometic/authyarn add @sometic/auth-oidc @sometic/authUsage
Configure OIDC and start the authorize redirect:
import { createAuth, createMemoryAuthStorage } from "@sometic/auth";
import { createOidcAuthProvider } from "@sometic/auth-oidc";
const provider = createOidcAuthProvider({
clientId: "my-spa",
redirectUri: "https://app.example.com/oauth/callback",
issuer: "https://auth.example.com",
scopes: ["openid", "profile", "email"],
});
const auth = createAuth({
provider,
storage: createMemoryAuthStorage(),
});
const { authorizationUrl, state } = await auth.startOAuth({
provider: "oidc",
redirectUri: "https://app.example.com/oauth/callback",
});
window.location.assign(authorizationUrl);Complete the callback with the authorization code:
await auth.completeOAuth({
provider: "oidc",
code: new URLSearchParams(location.search).get("code") ?? "",
state: new URLSearchParams(location.search).get("state") ?? "",
redirectUri: "https://app.example.com/oauth/callback",
});Peers / when not to use
Depends on @sometic/auth and @sometic/core. Requires Web Crypto (crypto.subtle) for PKCE.
Prefer @sometic/auth-local for first-party password APIs, or platform adapters for Firebase/Supabase. Do not use this package for resource-owner password grants; it is Authorization Code + PKCE oriented.
Docs
License
MIT
