Federation
Access Token Consumer
This step generates an AccessTokenConsumer AuthState which
is able to validate access tokens issued by an OAuth 2.0 Authorization Server / OpenID Provider.
Use this step in the Initial Authentication Flow of a Authentication Realm
to provide a resource server for REST services.
The access token has to be sent as Bearer token in the Authorization header.
The content of the token will be stored in session variables prefixed with oauth2.token.claim..
The sub claim of the access token will be used as user ID for nevisAuth.
This is technically sufficient for authentication.
However, it is recommended to perform additional checks in subsequent steps.
For instance, you may use a nevisIDM User Lookup step to look up a user in nevisIDM.
When the access token is invalid a 403 forbidden will be returned.
This pattern is experimental and it has some limitations.
For instance, it is assumed that the authorization server is running Nevis and
is set up by a OAuth 2.0 Authorization Server / OpenID Provider pattern that is part of this project.
If you need improvements for this pattern, please create a feature request.
On Success
Assign a step to continue with after successfully validating the token.
On Missing Token
Assign a step to continue with when no token was sent.
If nothing is assigned then authentication will fail with an error.
OAuth 2.0 Authorization Server / OpenID Provider
Assign the OAuth 2.0 Authorization Server / OpenID Provider
which has issued the access token.
Note that this step works in combination with Nevis OAuth 2.0 Authorization Server / OpenID Provider
only and the other pattern has to be in the same project.
Apple Login Step
Setup social login, using Apple as OpenID Connect provider.
Client ID
ClientID is Identifier provided by Apple when you register Apple as IdP service.
Client Secret
The Client Secret is a JWT token generated by using a private key provided by Apple. Please follow the instructions here.
You can generate the client secret by yourself and configure it here, or upload the Private Key to generate the client secret automatically. Only private key or client secret can be use at the time
Return Path
The callback URI to go to after a successful login with Apple.
This will create an endpoint in your host config.
The URL will be a combination of the Frontend Address of the Virtual Host and the value configured here.
For example, let's assume that you have configured:
- Return Path:
/oidc/apple/ - Frontend Address:
https://nevis.net
Then the URL will be https://nevis.net/oidc/apple/.
Use the exact: prefix to use the given path as-is.
Without this prefix a normal mapping with /* will be generated and thus sub-paths will be accessible as well.
Scope(s)
Select the requested scopes for getting user information from Apple.
The default is email and thus minimal information will be returned.
The scope openid will always be added as Apple uses OpenID Connect.
Virtual Host
Assign a Virtual Host which shall serve as entry point for the callback from social login provider.
In case your host has
- 1 address, that address will be used
- many addresses with
- 1 https, and many http, the https will be used without warning
- mix between http and https, the 1st https will be used with warning
- single scheme (http or https only) the 1st address will be used with warning
E.g.
http://nevis.net
http://nevis-security.net
https://nevis.net
https://nevis-security.net
The https://nevis.net will be used as the host for Apple callback
On Success
The step executed after a successful authentication.
If no step is configured here the process ends with AUTH_DONE.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Step as the last step of the Authentication process
to redirect back to original URL.
On Failure
The step that will be executed if the authentication fails.
If no step is configured here the process ends with AUTH_ERROR.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Failure Step as the last step of the Authentication process
to redirect back to original URL.
Private Key
Private key provided by Apple. Find out more here.
If you upload your private key here and set the Issuer, the pattern will automatically generate the Client Secret.
If you do not want to configure your private key, you have to set the Client Secret instead.
Issuer
The issuer registered claim identifies the principal that issued the client secret.
Since the client secret belongs to your developer team, use your 10-character Team ID associated with your developer account.
Find out more here.
nevisIDM
Choose which nevisIDM instance you want to store the user's information after logged in with social login provider.
Client External ID
The ExtId of the client in nevisIDM that will be used to store the user
On User Not Found
Configure the authentication flow to be executed when no user was found and the email provided by social account does not exist.
The authentication flow must contain the Social Login Create User pattern if a new user shall be created.
Note: Please select scope email and profile for getting user's information from social account.
On User Found
Configure the Authentication Flow in case no user with Subject/ID from social account was found but email does exist in nevisIDM. The Authentication Flow must contain:
Social Login Link Userpattern to link an existing user in IDM with Subject/ID of social account.Social Login Doneto end the social login flow after some other action(s).
Note: Please select scope email and profile for getting user's information from social account.
Claims Request
The claims request parameter. This value is expected to be formatted in JSON and does not accept trailing spaces nor tabs.
User ID Field
Logged userId will automatically get from social account. But you can change the userId by using this field.
Additional Auth Request Parameters
Arbitrary additional request parameters used in the authentication request. The property supports variable substitution.
Example:
[paramName]=[paramValue]
Button Label
Enter the text that should be displayed for the end-user on the social login button, and provide translations for this label on the Authentication Realms.
Facebook Login Step
Set up social login, using Facebook as OpenID Connect provider.
Client ID
ClientID is App ID provided by Facebook when you register Facebook as IdP service.
Client Secret
Client Secret is App Secret provided by Facebook when you register Facebook as IdP service.
Return Path
The callback URI to go to after a successful login with Facebook.
This will create an endpoint in your host config.
The URL will be a combination of the Frontend Address of the Virtual Host and the value configured here.
For example, let's assume that you have configured:
- Return Path:
/oidc/facebook/ - Frontend Address:
https://nevis.net
Then the URL will be https://nevis.net/oidc/facebook/.
Use the exact: prefix to use the given path as-is.
Without this prefix a normal mapping with /* will be generated and thus sub-paths will be accessible as well.
Scope(s)
Select the request scopes for getting user information from Facebook.
The default is email and thus minimal information will be returned.
Select public_profile to return additional user information.
Scope offline_access is not supported as Facebook has removed this scope.
Virtual Host
Assign a Virtual Host which shall serve as entry point for the callback from social login provider.
In case your host has
- 1 address, that address will be used
- many addresses with
- 1 https, and many http, the https will be used without warning
- mix between http and https, the 1st https will be used with warning
- single scheme (http or https only) the 1st address will be used with warning
E.g.
http://nevis.net
http://nevis-security.net
https://nevis.net
https://nevis-security.net
The https://nevis.net will be used as the host for Apple callback
On Success
The step executed after a successful authentication.
If no step is configured here the process ends with AUTH_DONE.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Step as the last step of the Authentication process
to redirect back to original URL.
On Failure
The step that will be executed if the authentication fails.
If no step is configured here the process ends with AUTH_ERROR.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Failure Step as the last step of the Authentication process
to redirect back to original URL.
nevisIDM
Choose which nevisIDM instance you want to store the user's information after logged in with social login provider.
Client External ID
The ExtId of the client in nevisIDM that will be used to store the user
On User Not Found
Configure the authentication flow to be executed when no user was found and the email provided by social account does not exist.
The authentication flow must contain the Social Login Create User pattern if a new user shall be created.
Note: Please select scope email and profile for getting user's information from social account.
On User Found
Configure the Authentication Flow in case no user with Subject/ID from social account was found but email does exist in nevisIDM. The Authentication Flow must contain:
Social Login Link Userpattern to link an existing user in IDM with Subject/ID of social account.Social Login Doneto end the social login flow after some other action(s).
Note: Please select scope email and profile for getting user's information from social account.
Claims Request
The claims request parameter. This value is expected to be formatted in JSON and does not accept trailing spaces nor tabs.
User ID Field
Logged userId will automatically get from social account. But you can change the userId by using this field.
Additional Auth Request Parameters
Arbitrary additional request parameters used in the authentication request. The property supports variable substitution.
Example:
[paramName]=[paramValue]
Button Label
Enter the text that should be displayed for the end-user on the social login button, and provide translations for this label on the Authentication Realms.
Generic Social Login Step
Use to set up a generic social login, either using OAuth2 or OpenID Connect.
Provider Type
The provider type of the social account: either OpenID Connect or OAuth2.
Client ID
The identifier provided by the social account when you register with it as the IdP service.
Client Secret
The secret of the client ID that has been set in the OAuth/OpenID Connect configuration of the social account.
Return Path
The callback URI to go to after a successful login with the social account.
This will create an endpoint in your host config.
The URL will be a combination of the Frontend Address of the Virtual Host and the value configured here.
For example, let's assume that you have configured:
- Return Path:
/oidc/app/ - Frontend Address:
https://nevis.net
Then the URL will be https://nevis.net/oidc/app/.
Use the exact: prefix to use the given path as-is.
Without this prefix a normal mapping with /* will be generated and thus sub-paths will be accessible as well.
Scope(s)
The request scope(s) for getting the user information from the social account. The default value is email.
The scope openid will be added automatically if providerType is set to OpenID Connect.
Scope offline_access for generate refresh token.
Virtual Host
Assign a Virtual Host which shall serve as entry point for the callback from social login provider.
In case your host has
- 1 address, that address will be used
- many addresses with
- 1 https, and many http, the https will be used without warning
- mix between http and https, the 1st https will be used with warning
- single scheme (http or https only) the 1st address will be used with warning
E.g.
http://nevis.net
http://nevis-security.net
https://nevis.net
https://nevis-security.net
The https://nevis.net will be used as the host for Apple callback
On Success
The step executed after a successful authentication.
If no step is configured here the process ends with AUTH_DONE.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Step as the last step of the Authentication process
to redirect back to original URL.
On Failure
The step that will be executed if the authentication fails.
If no step is configured here the process ends with AUTH_ERROR.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Failure Step as the last step of the Authentication process
to redirect back to original URL.
Client Secret Method
The method used for authenticating the client. It can be either Basic Authentication or POST.
The default value is Basic Authentication.
Response Mode
The mode used for the responses of the server. It can be either Query or Form POST.
The default value is Query.
PKCE
Setting for PKCE in Authorization/Authentication request.
- enabled, the Code Challenge and Code Verifier will be included in the Authorization/Authentication request.
- disabled (default), the Code Challenge and Code Verifier will not be included in the Authorization/Authentication request.
PKCE Secret
Allow to set the secret for PKCE. The secret format should follow RFC 7636.
Code Challenge Method
Setting for PKCE Code Challenge Method.
- plain (default), the Code Challenge will be sent with raw format.
- S256, the Code Challenge will be hashed and base 64 encoded.
Provider Endpoint
The provider endpoint that contains the configuration of the OpenID Connect server.
It's required when providerType has the value OpenID Connect.
Authorization Endpoint
The authorization endpoint of the OAuth2 provider.
Required when Provider Type is set to OAuth2.
Token Endpoint
The token endpoint of the OAuth2 server.
It's required when providerType has the value OAuth2.
User Information Endpoint
The user information endpoint of the OAuth2 server.
It's required when providerType has the value OAuth2.
JWKS Endpoint
The JWKS endpoint of the OAuth2 server.
It's optional when Provider Type has the value OAuth2.
nevisIDM
Choose which nevisIDM instance you want to store the user's information after logged in with social login provider.
Client External ID
The ExtId of the client in nevisIDM that will be used to store the user.
On User Not Found
Configure the authentication flow to be executed when no user was found and the email provided by social account does not exist.
The authentication flow must contain the Social Login Create User pattern if a new user shall be created.
Note: Please select scope email and profile for getting user's information from social account.
On User Found
Configure the Authentication Flow in case no user with Subject/ID from social account was found but email does exist in nevisIDM. The Authentication Flow must contain:
Social Login Link Userpattern to link an existing user in IDM with Subject/ID of social account.Social Login Doneto end the social login flow after some other action(s).
Note: Please select scope email and profile for getting user's information from social account.
Account Linking - User Property
Enter the name of the nevisIDM user property that is used for linking the account.
The property will contain the value of the sub claim of the social login provider.
This pattern will ensure that the property is created in nevisIDM by contributing to the generation of the nevisIDM configuration.
The pattern adds a property definition file to /var/opt/nevisidm/<instance>/conf/import/user_<name>.json.
This file is interpreted by nevisIDM during startup.
Before the May 2025 release, the sanitized pattern name was used for this property. This is not recommended anymore, as the account link will break when the pattern is renamed.
To avoid this problem, it is now recommended to configure this setting. If you are upgrading from a previous version you must use the property name which was used so far.
First Name Claim
The claim that contains the first name of the logged-in user in the social account.
The default value is given_name.
Second Name Claim
The claim that contains the second name of the logged-in user in the social account.
The default value is family_name.
Email Claim
The claim that contains the e-mail of the logged-in user in the social account.
The default value is email.
Subject Claim
The claim that contains the subject of the logged-in user in the social account.
The default value is sub.
Claims Request
The claims request parameter. This value is expected to be formatted in JSON and does not accept trailing spaces nor tabs.
User ID Field
Logged userId will automatically get from social account. But you can change the userId by using this field.
Additional Auth Request Parameters
Arbitrary additional request parameters used in the authentication request. The property supports variable substitution.
Example:
[paramName]=[paramValue]
Button Label
The text that should be displayed for the end-user on the social login button, and provide translations for this label on the Authentication Realms.
Button CSS class
The css class that apply for the social login button. Ensure that the Login Template used in your realm pattern includes a CSS file which defines the CSS class.
Button Logo Path
The path to logo file of the social login provider. This path is the path of logo file which you which uploaded at Login template in Realm pattern. E.g:
In the zip file the icon with path /webdata/resources/icons/icon.csv, the input is /icons/icon.csv
Google Login Step
Set up social login, using Google as OpenID Connect provider.
Client ID
ClientID is Client ID provided by Google when you create a OAUTH 2.0 credential in Google.
Client Secret
Client Secret is Client Secret provided by Google when you create a OAUTH 2.0 credential in Google.
Return Path
The callback URI to go to after a successful login with Google.
This will create an endpoint in your host config.
The URL will be a combination of the Frontend Address of the Virtual Host and the value configured here.
For example, let's assume that you have configured:
- Return Path:
/oidc/google/ - Frontend Address:
https://nevis.net
Then the URL will be https://nevis.net/oidc/google/.
Use the exact: prefix to use the given path as-is.
Without this prefix a normal mapping with /* will be generated and thus sub-paths will be accessible as well.
Virtual Host
Assign a Virtual Host which shall serve as entry point for the callback from social login provider.
In case your host has
- 1 address, that address will be used
- many addresses with
- 1 https, and many http, the https will be used without warning
- mix between http and https, the 1st https will be used with warning
- single scheme (http or https only) the 1st address will be used with warning
E.g.
http://nevis.net
http://nevis-security.net
https://nevis.net
https://nevis-security.net
The https://nevis.net will be used as the host for Apple callback
Scope(s)
Select the request scope(s) for getting user information from Google. Default scopes is email.
Scope openid will be added automatically because Google is implement based on OpenID protocol.
Scope offline_access for generate refresh token. This scope will transfer to access_type=offline request parameter for matching with Google spec
On Success
The step executed after a successful authentication.
If no step is configured here the process ends with AUTH_DONE.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Step as the last step of the Authentication process
to redirect back to original URL.
On Failure
The step that will be executed if the authentication fails.
If no step is configured here the process ends with AUTH_ERROR.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Failure Step as the last step of the Authentication process
to redirect back to original URL.
nevisIDM
Choose which nevisIDM instance you want to store the user's information after logged in with social login provider.
Client External ID
The ExtId of the client in nevisIDM that will be used to store the user
On User Not Found
Configure the authentication flow to be executed when no user was found and the email provided by social account does not exist.
The authentication flow must contain the Social Login Create User pattern if a new user shall be created.
Note: Please select scope email and profile for getting user's information from social account.
On User Found
Configure the Authentication Flow in case no user with Subject/ID from social account was found but email does exist in nevisIDM. The Authentication Flow must contain:
Social Login Link Userpattern to link an existing user in IDM with Subject/ID of social account.Social Login Doneto end the social login flow after some other action(s).
Note: Please select scope email and profile for getting user's information from social account.
Claims Request
The claims request parameter. This value is expected to be formatted in JSON and does not accept trailing spaces nor tabs.
User ID Field
Logged userId will automatically get from social account. But you can change the userId by using this field.
Additional Auth Request Parameters
Arbitrary additional request parameters used in the authentication request. The property supports variable substitution.
Example:
[paramName]=[paramValue]
Button Label
Enter the text that should be displayed for the end-user on the social login button, and provide translations for this label on the Authentication Realms.
Microsoft Login Step
Set up social login, using Microsoft as OpenID Connect provider.
Client ID
ClientID is Application (client) ID provided by Microsoft when you create an Application Microsoft.
Client Secret
Client Secret is Client Secret provided by Microsoft when you create an Application Credentials & Secrets in Microsoft.
Return Path
The callback URI to go to after a successful login with Microsoft.
This will create an endpoint in your host config.
The URL will be a combination of the Frontend Address of the Virtual Host and the value configured here.
For example, let's assume that you have configured:
- Return Path:
/oidc/microsoft/ - Frontend Address:
https://nevis.net
Then the URL will be https://nevis.net/oidc/microsoft/.
Use the exact: prefix to use the given path as-is.
Without this prefix a normal mapping with /* will be generated and thus sub-paths will be accessible as well.
Scope(s)
Select the request scope(s) for getting user information from Microsoft. Default scopes is email.
Scope openid will be added automatically because Microsoft is implement based on OpenID protocol.
Scope offline_access for generate refresh token.
Virtual Host
Assign a Virtual Host which shall serve as entry point for the callback from social login provider.
In case your host has
- 1 address, that address will be used
- many addresses with
- 1 https, and many http, the https will be used without warning
- mix between http and https, the 1st https will be used with warning
- single scheme (http or https only) the 1st address will be used with warning
E.g.
http://nevis.net
http://nevis-security.net
https://nevis.net
https://nevis-security.net
The https://nevis.net will be used as the host for Apple callback
On Success
The step executed after a successful authentication.
If no step is configured here the process ends with AUTH_DONE.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Step as the last step of the Authentication process
to redirect back to original URL.
On Failure
The step that will be executed if the authentication fails.
If no step is configured here the process ends with AUTH_ERROR.
In case you change this to your custom step(s),
you can assign pattern Social Login Final Failure Step as the last step of the Authentication process
to redirect back to original URL.
nevisIDM
Choose which nevisIDM instance you want to store the user's information after logged in with social login provider.
Client External ID
The ExtId of the client in nevisIDM that will be used to store the user
On User Not Found
Configure the authentication flow to be executed when no user was found and the email provided by social account does not exist.
The authentication flow must contain the Social Login Create User pattern if a new user shall be created.
Note: Please select scope email and profile for getting user's information from social account.
On User Found
Configure the Authentication Flow in case no user with Subject/ID from social account was found but email does exist in nevisIDM. The Authentication Flow must contain:
Social Login Link Userpattern to link an existing user in IDM with Subject/ID of social account.Social Login Doneto end the social login flow after some other action(s).
Note: Please select scope email and profile for getting user's information from social account.
Application Type
The application type that you choose when you create your application in Microsoft. We are supporting 3 types
- common
- organizations
- consumers
Please follow this document to select your application type correctly
Tenant ID
Enter the Tenant ID of your Azure Active Directory.
This setting is used when Application Type is set to organizations.
Check Microsoft documentation on How to find your Azure Active Directory tenant ID.
Claims Request
The claims request parameter. This value is expected to be formatted in JSON and does not accept trailing spaces nor tabs.
User ID Field
Logged userId will automatically get from social account. But you can change the userId by using this field.
Additional Auth Request Parameters
Arbitrary additional request parameters used in the authentication request. The property supports variable substitution.
Example:
[paramName]=[paramValue]
Button Label
Enter a label for the social login button.
Translations for this label can be configured in the Authentication Realm pattern.
nevisMeta REST Service
The pattern exposes the nevisMeta REST API on a nevisProxy Virtual Host.
The REST API is exposed on the path /nevismeta/rest.
nevisMeta
Reference the nevisMeta Instance.
Virtual Host(s)
Assign a Virtual Host which shall serve as entry point.
Authentication Realm
Assign a realm pattern which authenticates access to nevisMeta.
Application Access Token
Assign a Nevis SecToken pattern.
The token informs nevisMeta about the authenticated user.
If you are not using automatic key management then you also have to configure nevisMeta Instance / SecToken Signer Trust Store
so that the signer certificate is trusted.
Additional Settings
Assign add-on patterns to customize the behavior of this service.
Example use cases:
Authorization Policyto enforce roles or an authentication level.URL Handlingto redirect or forward requests.HTTP Header Customizationto add, replace, or remove HTTP headers in requests or responses.
nevisMeta Web Console
Sets up the nevisMeta Web Console, which is a component supporting the setup of OAuth2 and OpenID Connect for nevisAuth.
You can access the Web console on the assigned Virtual Host.
For instance, let's say your domain is example.com, and you have entered https://example.com as a Frontend Addresses in the Virtual Host pattern. This means that you can access the Web console on https://example.com/nevismeta/.
nevisMeta
Reference the nevisMeta Instance.
Virtual Host(s)
Assign a Virtual Host which shall serve as entry point.
Trust Store
Assign the Trust Store provider for outbound TLS connections. If no pattern is assigned a trust store will be provided by nevisAdmin 4 automatic key management.
Hostname Validation
Enable to verify that the hostname on the certificate presented by the backend matches the hostname of nevisMeta
Key Store
Assign a key store if you want to use 2-way TLS for the connection between nevisProxy and nevisMeta.
Outbound Client Authentication
Controls whether the service access presents a client certificate on outbound TLS connections.
automatic follows the referenced target's server-side client-authentication setting. required ensures that client authentication is used, preserving an explicitly configured key store and generating an implicit identity only when no key store is configured. disabled prevents client authentication and is rejected when the referenced target requires it.
Authentication Realm
Assign a realm pattern which authenticates access to nevisMeta.
Application Access Token
A Nevis SecToken pattern must be assigned here.
The token will be issued after authentication and propagated to nevisMeta.
The user must have the role nevisMeta.admin.
Request Validation (ModSecurity)
off- no request validationstandard- uses ModSecurity OWASP Core Rule Set (CRS) with default paranoia level 1 - Basic securitycustom- configureRequest Validation SettingsviaAdditional Settingslog only- usesstandardin log only mode
Additional Settings
Assign add-on patterns to customize the behavior of this service.
Example use cases:
Authorization Policyto enforce roles or an authentication level.URL Handlingto redirect or forward requests.HTTP Header Customizationto add, replace, or remove HTTP headers in requests or responses.
OAuth 2.0 / OpenID Connect Dynamic Client Registration Endpoint
Links to a Dynamic Client Registration endpoint for OAuth 2.0 / OpenID Connect.
The information is by OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
Endpoint Path
Enter the URL of the registration endpoint.
Note that if the value contains a hostname, this pattern will not set up a registration endpoint, it just provides information about that endpoint.
The information is then used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
The prefix exact: is not supported here, enter the path as-is.
OAuth 2.0 / OpenID Connect JWKs Endpoint
Sets up a JWKs endpoint for OAuth 2.0 / OpenID Connect.
Endpoint Path
If you enter a path the REST service will be generated and exposed on the nevisProxy Virtual Host
assigned to the OAuth 2.0 Authorization Server / OpenID Provider.
The prefix exact: is not supported here, enter the path as-is.
If you enter a URL no REST service will be generated. Use this variant if you want to use an external service.
Either way, the information will be used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
OAuth 2.0 / OpenID Connect Metadata Endpoint
Sets up a Metadata endpoint for OAuth 2.0 / OpenID Connect.
Endpoint Path
If you enter a path the REST service will be generated and exposed on the nevisProxy Virtual Host
assigned to the OAuth 2.0 Authorization Server / OpenID Provider.
The prefix exact: is not supported here, enter the path as-is.
If you enter a URL no REST service will be generated. Use this variant if you want to use an external service.
Either way, the information will be used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
OAuth 2.0 / OpenID Connect Pushed Authorization Request Endpoint
Sets up a Pushed Authorization Request endpoint for OAuth 2.0 / OpenID Connect.
Endpoint Path
If you enter a path the REST service will be generated and exposed on the nevisProxy Virtual Host
assigned to the OAuth 2.0 Authorization Server / OpenID Provider.
The prefix exact: is not supported here, enter the path as-is.
If you enter a URL no REST service will be generated. Use this variant if you want to use an external service.
Either way, the information will be used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
Protected Endpoint
Set Basic authentication for REST Service of OAuth 2.0 Authorization Server / OpenID Provider.
When this property is enabled, the request must include Authentication Header.
The header is a combination of clientID and clientSecret with base64 encoded
Request Timeout
Configure how the PAR request shall be valid.
For security reasons, we suggest to keep this duration as low as possible.
If not set, the default in the nevisAuth component (90s) applies.
OAuth 2.0 / OpenID Connect Token Introspection Endpoint
Sets up a Token Introspection endpoint for OAuth 2.0 / OpenID Connect.
Endpoint Path
If you enter a path the REST service will be generated and exposed on the nevisProxy Virtual Host
assigned to the OAuth 2.0 Authorization Server / OpenID Provider.
The prefix exact: is not supported here, enter the path as-is.
If you enter a URL no REST service will be generated. Use this variant if you want to use an external service.
Either way, the information will be used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
Protected Endpoint
Set Basic authentication for REST Service of OAuth 2.0 Authorization Server / OpenID Provider.
When this property is enabled, the request must include Authentication Header.
The header is a combination of clientID and clientSecret with base64 encoded
OAuth 2.0 / OpenID Connect Token Revocation Endpoint
Sets up a Token Revocation endpoint for OAuth 2.0 / OpenID Connect.
Endpoint Path
If you enter a path the REST service will be generated and exposed on the nevisProxy Virtual Host
assigned to the OAuth 2.0 Authorization Server / OpenID Provider.
The prefix exact: is not supported here, enter the path as-is.
If you enter a URL no REST service will be generated. Use this variant if you want to use an external service.
Either way, the information will be used by the OAuth 2.0 / OpenID Connect Metadata Endpoint to provide metadata.
Protected Endpoint
Set Basic authentication for REST Service of OAuth 2.0 Authorization Server / OpenID Provider.
When this property is enabled, the request must include Authentication Header.
The header is a combination of clientID and clientSecret with base64 encoded
OAuth 2.0 / OpenID Connect User Info
An OAuth 2.0 Authorization Server / OpenID User Info returns information about the authenticated user.
Virtual Host(s)
Assign a Virtual Host which shall serve as entry point.
Authentication Realm
Assign a realm which shall be exposed to get user information of an OAuth2 Authorization Server or OpenID Connect Provider.
Endpoint
Enter the path where the endpoint shall be exposed on nevisProxy.
Use the exact: prefix to expose only the given path.
Without this prefix sub-paths will be accessible as well.
This is because a normal mapping with /* at the end will be created in nevisProxy.
Signer
Configure the key material which is used to validate tokens. This signer must be the same signer that use to sign the tokens.
nevisIDM
Assign a nevisIDM Instance or nevisIDM Connector to get user information.
OAuth 2.0 Authorization Server / OpenID Provider
An OAuth 2.0 Authorization Server / OpenID Provider can issue tokens for a client, considering the requested scopes, claims, and end user consent.
See AuthorizationServer for details.
The pattern is experimental. We recommend using it for prototyping configuration only, as there may be breaking changes in future versions.
The metadata of OAuth 2.0 clients is managed in nevisMeta.
The pattern nevisMeta Web Console should be configured as well.
Virtual Host
Assign a Virtual Host which shall serve as entry point.
Authorization Path
This is the path where relying parties redirect the browser to.
Example use cases:
- OAuth: acquire an access and refresh tokens
- OpenID Connect: acquire access, refresh and ID tokens
Use the exact: prefix to expose only the given path.
Without this prefix sub-paths will be accessible as well.
This is because a normal mapping with /* at the end will be created in nevisProxy.
Token Path
The endpoint to exchange the authorization code for tokens.
Use the exact: prefix to expose only the given path.
Without this prefix sub-paths will be accessible as well.
This is because a normal mapping with /* at the end will be created in nevisProxy.
Authentication Realm
Assign a realm which shall be exposed as an OAuth2 Authorization Server or OpenID Connect Provider.
Signer
Configure the key material which is used to sign issued codes and tokens.
Access Token Format
Choose between:
JWE: the access token will be encrypted. This is the default.
The token is considered opaque and thus resource servers need to call the token introspection endpoint to validate the token.
JWS: the access token will not be encrypted. Choose this mode to get a signed token
which can be validated without calling the token introspection endpoint.
Assign the OAuth 2.0 / OpenID Connect JWKs Endpoint pattern to publish the public signing key,
so that resource servers can validate the signature.
OpenID Connect
If enabled the scope openid is allowed for this client.
OpenID Connect Issuer
Enter the issuer for OpenID Connect.
The value must be a case-sensitive URL using the https scheme that contains at least scheme and host. The port number and path component are optional. No query or fragment components are allowed.
If not set the issuer will be calculated based on:
- the first
Frontend Addresswith schemehttpsof the assignedVirtual Host - the first
Frontend Path
Access Token Claims
Configure additional claims for the OAuth2.0 Access Token.
Claims are added if they have a value.
For instance, claims may be added when a certain scope is requested which includes them.
OpenID Connect defines the following scope values which may be requested to get claims:
profile. claims:name,family_name,given_name,middle_name,nickname,preferred_username,profile,picture,website,gender,birthdate,zoneinfo,locale,updated_at.email. claims:email,email_verifiedaddress. claims:addressphone. claims:phone_number,phone_number_verified
Examples:
given_name=${sess:ch.nevis.idm.User.firstName}
family_name=${sess:ch.nevis.idm.User.name}
email=${sess:ch.nevis.idm.User.email}
mobile=${sess:ch.nevis.idm.User.mobile}
ID Token Claims
Define claims for the OpenID Connect ID token.
For the value you can use a constant, a nevisAuth expression, an EL expression,
or refer to an inventory variable by using the ${var.<name>} syntax.
Note that you also have to do this for standard OpenID Connect claims.
The only exception are sub, iss which will always be added.
Here are some examples:
| Claim | Value |
|---|---|
given_name | ${sess:ch.nevis.idm.User.firstName} |
family_name | ${sess:ch.nevis.idm.User.name} |
email | ${sess:ch.nevis.idm.User.email} |
mobile | ${sess:ch.nevis.idm.User.mobile} |
customer | ${var.customer-number} |
Which claims will be added to the ID token depends on the incoming request.
Non-standard claims have to be requested using the claims request parameter.
Standard claims are added when a certain OpenID Connect scope is requested:
| Requested Scope | Added Claims |
|---|---|
profile | name, family_name, given_name, middle_name, nickname, preferred_username, profile, picture, website, gender, birthdate, zoneinfo, locale, updated_at |
email | email, email_verified |
address | address |
phone | phone_number, phone_number_verified |
ID Token Headers
Define custom JOSE headers for the OpenID Connect ID token.
For the value you can use a constant, a nevisAuth expression, an EL expression,
or refer to an inventory variable by using the ${var.<name>} syntax.
The header name must be a valid JOSE header parameter name. For encrypted ID tokens, custom headers are added to the outer JWE header.
Examples:
| Header | Value |
|---|---|
typ | JWT |
custom_header | ${sess:ch.nevis.idm.User.customHeader} |
customer | ${var.customer-number} |
REST Endpoint(s)
Add extension services for OAuth 2.0 Authorization Server / OpenID Provider
JWK Set Key ID
When set to enabled a kid header value will be added to issued access and ID tokens.
The value allows the authorization server to explicitly signal a change of key material to recipients.
The meaning of the kid header is slightly different for signed and encrypted tokens.
nevisMeta
Assign a nevisMeta Instance or nevisMeta Connector.
nevisMeta is used to lookup metadata for the given
OAuth2 / OpenID Connect Setup (see Setup ID).
Setup ID
ID of the nevisMeta setup.
Create your setup via the nevisMeta Web Console.
Then the ID of the setup can be determined. There are several ways to do that:
- hover over the icon which links to the REST API
- export the setup and check the exported files
- Configure a
nevisMeta REST Service, login and send aGETto/nevismeta/rest/v2/modules/oauthv2/setups/
Cache Timeout
Caching of responses from a nevisMeta instance. After this time (in seconds), a response is considered outdated and attempts are made to update it.
nevisIDM
Assign a nevisIDM Instance or nevisIDM Connector.
Required when User Info is enabled.
Assignment is required to determine the URL for the REST API call to the nevisIDM user info endpoint.
User Info
When enabled, the nevisIDM user info endpoint is called to retrieve information about the authenticated user.
The following property will be added to the configuration of the AuthorizationServer AuthState:
<property name="openid.userInfoEndpointUri" value="https://<idm-host>:<idm-port>/nevisidm/api/oic1.0/userinfo"/>
For reasons of backward compatibility, the default is disabled.
The information from the user info endpoint is used to populate any claims in the returned ID and access tokens.
Auth Code Lifetime
How long an authorization code issued by the authorization server should be valid.
Refresh Token Rotation
Defines if a new Refresh Token is issued together with the Access Token on the Token Endpoint while exchanging a
refresh token for a new access token (grant_type=refresh_token).
- enabled, a new Refresh Token is issued, the existing Refresh token is deleted.
- disabled, the existing Refresh token is returned and remains valid.
Remove Empty Claim(s) In Token
Defines if the empty claim(s) will appear in the Access Token and ID Token.
- enabled: the ID Token and Access Token will not include empty claim(s).
- disabled (default): the ID Token and Access Token may include empty claim(s).
Audience Field Strategy
Defines whether the audience (aud) claim is added to the issued Access Tokens, following
RFC 9068 and RFC 8707.
- disabled (default): the Access Token will not contain the
audclaim. Theresourcerequest parameter is ignored. - resource: the audience is derived from the
resourcerequest parameter or from the configured resource servers in nevisMeta that own the requested scopes. The eligible resource servers must have theURLfield set in nevisMeta. Requires nevisMeta as the data source.
JWK Set Endpoint Trust Store
Assign a trust store for the outbound TLS connection to JWK Set endpoint for ID Token encryption.
Import the CA certificate of the JWK Set endpoint into this trust store.
Since version 4.38 nevisAuth trusts CA certificates included in the JDK.
Thus, it is not required to configure this.
However, you can still configure a trust store here to be as strict as possible.
JWK Set Endpoint Proxy
Forward proxy for the connection to the JWK Set endpoint for ID token encryption. Enter the hostname:port here
Example: proxy.your-internal-domain:3128
Invalid Client
Configure the step to execute after error when the client sending the request is not registered.
If no step is configured here the process ends and the error will display on UI.
Invalid Redirect URI
Configure the step to execute when the redirect_uri request parameter value is not registered for the client sending the request.
If no step is configured here the flow ends and an error will be displayed.
Valid Authorization Request Authentication Required
The nevisMeta UI has a setting on the Client called Force Reauthentication.
If enabled, users need to authenticate for every invocation of the Authorization Path.
To ensure that this setting works out of the box, this pattern generates configuration
which always dispatches the request into the Initial Authentication Flow of the assigned Authentication Realm.
If you want to use a different authentication flow for re-authentication, then assign a different step here.
When configured, a ResultCond with name valid-authorization-request-authentication-required will be added.
Authentication Successful Without Login
Configure the step to execute after authorization request is valid and end-user authentication can be skipped.
If no step is configured here the process ends and the final AUTH_DONE will be reached.