OpenID Connect Discovery

How a Relying Party fetches the OpenID Provider's configuration document and public keys to bootstrap an OIDC integration.

Others

Before a Relying Party can use OpenID Connect, it must learn the OpenID Provider's endpoint URLs, supported algorithms, and public signing keys. The discovery mechanism lets a client bootstrap this configuration automatically by fetching a well-known JSON document at <issuer>/.well-known/openid-configuration, then optionally pre-fetching the signing keys at the returned jwks_uri.

OpenID ProviderClient AppOpenID ProviderClient AppGET /.well-known/openid-configuration1200 OK - Provider Metadata JSON2GET <jwks_uri>3200 OK - JWKS (public signing keys)4Cache endpoints and public keys5

Official Specifications

Additional Resources

Back to all diagrams