OneIdAuthConfig class
Configuration required to construct an OneIdAuth.
The SDK speaks standard OAuth 2.0 Authorization Code flow with PKCE (RFC 6749 + RFC 7636, per the native-app guidance in RFC 8252), with every token DPoP-bound (RFC 9449) to a key held in Android Keystore / iOS Secure Enclave. It doesn't care whether environment's host is the identity provider itself or a backend-for-frontend fronting it — either way it just needs an OIDC-shaped discovery document (or explicit endpoint overrides) and a public client id.
- Annotations
Constructors
-
OneIdAuthConfig({required OneIdEnvironment environment, required String clientId, required String redirectUrl, List<
String> ? scopes, String? discoveryUrl, String? authorizationEndpoint, String? tokenEndpoint, String? endSessionEndpoint, Duration connectTimeout = const Duration(seconds: 10), Duration receiveTimeout = const Duration(seconds: 30)})
Properties
-
Explicit authorization endpoint, bypassing discovery. Set this (with
tokenEndpoint) if the deployment doesn't publish a discovery
document yet.
final
- clientId → String
-
The public client id registered for this application.
final
- connectTimeout → Duration
-
Timeout for establishing the connection to the API.
final
- discoveryUrl → String
-
OIDC discovery document URL. Defaults to
<environment.baseUrl>/.well-known/openid-configuration.final - endSessionEndpoint → String?
-
Explicit end-session (logout) endpoint, bypassing discovery. Optional
even when authorizationEndpoint/tokenEndpoint are set — not every
deployment supports RP-initiated logout.
final
- environment → OneIdEnvironment
-
Which deployment to authenticate against.
final
- hasExplicitEndpoints → bool
-
Whether enough manual endpoint overrides are present to skip OIDC
discovery entirely.
no setter
- hashCode → int
-
The hash code for this object.
no setteroverride
- receiveTimeout → Duration
-
Timeout for receiving a response after the request has been sent.
final
- redirectUrl → String
-
Where the authorization server redirects back to after the user
authenticates — a custom scheme or app link registered on both
platforms and with the authorization server.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
scopes
→ List<
String> -
Scopes requested during authorization. Defaults to
openid profile offline_access(the last is what obtains a refresh token).final - tokenEndpoint → String?
-
Explicit token endpoint, bypassing discovery.
final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
override