# OIDC and OAuth 2.0

[OpenID Connect](https://openid.net/specs/openid-connect-core-1_0.html) (OIDC) extends the authentication and authorization mechanisms of OAuth 2.0 with identity-focused security features like ID tokens and user profiles. Mosaic supports an OIDC-based integration option for hosted login using secure FIDO2 WebAuthn biometrics, and social providers like Google, Facebook, Apple, and LINE. <br><br>Decoupled authentication flows are supported using [Client-Initiated Backchannel Authentication (CIBA)](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0.html) or using the [OAuth Device Flow](https://www.rfc-editor.org/rfc/rfc8628) for input-limited devices.


## Servers

Sandbox environment
```
https://api.sbx.transmitsecurity.io/cis
```

US production environment
```
https://api.transmitsecurity.io/cis
```

EU production environment
```
https://api.eu.transmitsecurity.io/cis
```

CA production environment
```
https://api.ca.transmitsecurity.io/cis
```

AU production environment
```
https://api.au.transmitsecurity.io/cis
```

JP production environment
```
https://api.gasne1-ts01.transmitsecurity.io/cis
```

## Security

## Download OpenAPI description

 - [OIDC and OAuth 2.0](https://developer.transmitsecurity.com/_bundle/openapi/user/oidc.openapi.yaml)

 - [GET /oidc/auth](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcauthenticate.md): Start an authentication process. If the process is successful, an authorization code is returned to the redirect URI specified in the request. (See [OIDC spec](https://openid.net/specs/openid-connect-
 - [POST /oidc/backchannel](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcbackchannelauthenticate.md): Start a backchannel authentication process (See [CIBA spec](https://openid.net/specs/openid-client-initiated-backchannel-authentication-core-1_0-final.html#rfc.section.7)). The request can either be u
 - [POST /oidc/device/auth](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcdeviceauth.md): Initiate the device flow (See [OAuth 2.0 Device Authorization Grant (RFC 8628)](https://www.rfc-editor.org/rfc/rfc8628)). This call returns a user code and verification URI for the user to approve or
 - [POST /oidc/token](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidctoken.md): Retrieves tokens in various OIDC/OAuth flows. It's used to retrieve an ID token and user access token upon successful user authentication (for an [authorization code flow](https://openid.net/specs/ope
 - [POST /oidc/token/revocation](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcrevoketoken.md): Revoke a specific refresh token, making it no longer valid and forcing the user to re-authenticate if they need a new one.
 - [POST /oidc/token/introspection](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcintrospecttoken.md): Determine the active state of an OAuth 2.0 token and obtain meta-information about it (see [OAuth 2.0 Token Introspection — RFC 7662](https://www.rfc-editor.org/rfc/rfc7662)). The endpoint requires cl
 - [GET /oidc/me](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcuserinfoget.md): Return claims about the authenticated end-user **by sending a Bearer access token in the `Authorization` header**. The token must be issued with the `openid` scope. For more information, see the [OIDC
 - [POST /oidc/me](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcuserinfopost.md): Return claims about the authenticated end-user **by sending a Bearer access token as the form-encoded `access_token` body parameter**. The token must be issued with the `openid` scope. For more inform
 - [GET /oidc/session/end](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/endoidcsession.md): Terminates all the user’s active sessions for this tenant. Note that running this call does not revoke valid access tokens or refresh tokens. See [OIDC RP-Initiated Logout](https://openid.net/specs/op
 - [GET /oidc/jwks](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/oidcgetkeys.md): Returns the signing key used to validate the signature of the authorization request (per [OIDC spec](https://openid.net/specs/openid-connect-core-1_0.html#SigEnc))
 - [GET /oidc/.well-known/openid-configuration](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/getoidcconfiguration.md): Get all metadata for the OIDC server, including paths to relevant endpoints. (see [OIDC spec](https://openid.net/specs/openid-connect-discovery-1_0.html))
 - [POST /oidc/request](https://developer.transmitsecurity.com/openapi/user/oidc.openapi/other/pushedauthorizationrequest.md): Pushed authorization request (PAR) is a secure way to initiate the authorization flow. All parameters are sent in the body of the request (see [OAuth 2.0 Pushed Authorization Requests RFC](https://www
