OneIdAuthConfig class

Configuration required to construct an OneIdAuth.

The SDK speaks standard OAuth 2.0 Authorization Code flow with PKCE (RFC 6749 + RFC 7636, per the native-app guidance in RFC 8252), with every token DPoP-bound (RFC 9449) to a key held in Android Keystore / iOS Secure Enclave. It doesn't care whether environment's host is the identity provider itself or a backend-for-frontend fronting it — either way it just needs an OIDC-shaped discovery document (or explicit endpoint overrides) and a public client id.

Annotations

Constructors

OneIdAuthConfig({required OneIdEnvironment environment, required String clientId, required String redirectUrl, List<String>? scopes, String? discoveryUrl, String? authorizationEndpoint, String? tokenEndpoint, String? endSessionEndpoint, Duration connectTimeout = const Duration(seconds: 10), Duration receiveTimeout = const Duration(seconds: 30)})

Properties

authorizationEndpoint → String?
Explicit authorization endpoint, bypassing discovery. Set this (with tokenEndpoint) if the deployment doesn't publish a discovery document yet.
final
clientId → String
The public client id registered for this application.
final
connectTimeout → Duration
Timeout for establishing the connection to the API.
final
discoveryUrl → String
OIDC discovery document URL. Defaults to <environment.baseUrl>/.well-known/openid-configuration.
final
endSessionEndpoint → String?
Explicit end-session (logout) endpoint, bypassing discovery. Optional even when authorizationEndpoint/tokenEndpoint are set — not every deployment supports RP-initiated logout.
final
environment → OneIdEnvironment
Which deployment to authenticate against.
final
hasExplicitEndpoints → bool
Whether enough manual endpoint overrides are present to skip OIDC discovery entirely.
no setter
hashCode → int
The hash code for this object.
no setteroverride
receiveTimeout → Duration
Timeout for receiving a response after the request has been sent.
final
redirectUrl → String
Where the authorization server redirects back to after the user authenticates — a custom scheme or app link registered on both platforms and with the authorization server.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
scopes → List<String>
Scopes requested during authorization. Defaults to openid profile offline_access (the last is what obtains a refresh token).
final
tokenEndpoint → String?
Explicit token endpoint, bypassing discovery.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
override