npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

capacitor-oidc

v0.1.2

Published

OAuth 2.0 and OpenID Connect authentication for Capacitor web, iOS, and Android, powered by oidc-client-ts.

Readme

capacitor-oidc

npm CI license

capacitor-oidc is one OAuth 2.0 and OpenID Connect client for Capacitor web, iOS, and Android applications, powered by oidc-client-ts. It uses Authorization Code Flow with PKCE, native system authentication UI and secure storage on mobile, and standard browser navigation and storage on web.

Why capacitor-oidc?

  • Simple standards-based OAuth 2.0 and OIDC for Capacitor, without provider-specific SDKs.
  • One manager and configuration contract across web, iOS, and Android.
  • The familiar oidc-client-ts UserManager API, session objects, and events.
  • System authentication UI instead of an embedded WebView.
  • Secure native storage for OIDC transactions and sessions.
  • Refresh-token renewal when the app is active or resumes.
  • A native-readable session snapshot for app widgets.

On iOS, authentication uses ASWebAuthenticationSession. On Android, it uses AndroidX Auth Tab with its Custom Tab fallback.

Compatibility

| Target | Support | | --------- | -------------------------------------------- | | Capacitor | 7 and 8 | | iOS | 15 or newer; ASWebAuthenticationSession | | Android | API 24 or newer; Auth Tab or Custom Tab | | Flow | Authorization Code Flow with PKCE | | Providers | Compatible OAuth 2.0 and OpenID Connect APIs | | Web | Redirect or popup navigation |

Demo

This example signs in against a local Keycloak realm with Authorization Code Flow and PKCE, renews the session through its refresh token, and signs out at the provider.

Capacitor OIDC login, renewal, and logout on the iOS Simulator

Requirements

  • Capacitor 7 or 8
  • iOS 15 or newer
  • Android API 24 or newer
  • Android compile SDK 36, Java 21, and a compatible Android Gradle Plugin
  • an OAuth public client using Authorization Code Flow with PKCE
  • Web Crypto in every target runtime
  • CORS support for web application and Capacitor origins on OIDC HTTP endpoints

Never ship a client secret in a Capacitor application.

Install

npm install capacitor-oidc @capacitor/app
npx cap sync

Quick start

import { CapacitorUserManager } from 'capacitor-oidc';

const manager = await CapacitorUserManager.create({
  common: {
    authority: 'https://identity.example.com',
    client_id: 'public-app',
    scope: 'openid profile offline_access',
    automaticSilentRenew: true,
    revokeTokensOnSignout: true,
  },
  web: {
    settings: {
      redirect_uri: `${window.location.origin}/callback`,
      post_logout_redirect_uri: `${window.location.origin}/logout-callback`,
    },
  },
  native: {
    settings: {
      redirect_uri: 'com.example.app:/callback',
      post_logout_redirect_uri: 'com.example.app:/logout-callback',
    },
    options: { storageNamespace: 'primary' },
  },
});

await manager.signin();
const validUser = await manager.getValidUser(30);

await manager.signout();
await manager.dispose();

Register every configured redirect and post-logout redirect URI exactly at your provider, and register the native schemes in each native application. On the web callback route, call signinCallback(); on the web logout callback route, call signoutCallback(). The package detects the runtime and applies common, then web or native, then the matching ios or android override.

A runnable Keycloak-backed iOS application and its UI test live in example.

Documentation

Development

npm run verify
npm run verify:ios
npm run verify:android

Architecture decisions and contributor constraints are documented in ARCHITECTURE.md, REQUIREMENTS.md, and docs/adr.

License

Apache-2.0