These are the endpoints a relying party calls, generated from the service's OpenAPI contract. The same contract is available as OpenAPI (JSON). Every endpoint is on https://sso.aldelo.com. For how and when to call them, read the guides.
GET /.well-known/openid-configuration
OIDC discovery document
Responses
GET /.well-known/jwks.json
JSON Web Key Set
Responses
| Status | Content |
200 | application/json (JWKSet) |
503 | No body |
GET /authorize
OIDC authorize entry (HTML surface)
Parameters
| Name | In | Type | Required |
client_id | query | string | Yes |
redirect_uri | query | string (uri) | Yes |
response_type | query | string: one of code | Yes |
scope | query | string | Yes |
state | query | string | Yes |
code_challenge | query | string | Yes |
code_challenge_method | query | string: one of S256 | Yes |
prompt | query | string | No |
max_age | query | integer (int64) | No |
acr_values | query | string | No |
nonce | query | string | No |
organization_hint | query | string (uuid) | No |
Responses
| Status | Content |
200 | text/html |
302 | No body |
303 | No body |
400 | text/html |
404 | text/html |
503 | text/html |
GET /authorize/organization
Organization picker (HTML surface)
Parameters
| Name | In | Type | Required |
q | query | string | No |
after | query | string (uuid) | No |
before | query | string (uuid) | No |
Responses
| Status | Content |
200 | text/html |
302 | No body |
400 | text/html |
404 | text/html |
503 | text/html |
POST /oauth2/token
Token endpoint — authorization code exchange
Authentication: client secret (HTTP Basic) or none (public client with PKCE)
Request body: application/x-www-form-urlencoded (required)
| Field | Type | Required |
client_id | string | No |
client_secret | string | No |
code | string | Yes |
code_verifier | string | Yes |
grant_type | string: one of authorization_code | Yes |
redirect_uri | string | Yes |
scope | string | No |
Responses
| Status | Content |
200 | application/json |
400 | application/json |
401 | application/json |
429 | application/json |
503 | application/json |
Response 200 body
| Field | Type | Required |
access_token | string | Yes |
expires_in | integer (int64) | Yes |
id_token | string | No |
scope | string | Yes |
token_type | string: one of bearer | Yes |
Response 400 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 401 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 429 body
| Field | Type | Required |
error | object | No |
error.code | string | No |
error.correlation_id | string | No |
error.message | string | No |
Response 503 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
POST /oauth2/introspect
Token introspection (RFC 7662)
Authentication: client secret (HTTP Basic)
Request body: application/x-www-form-urlencoded (required)
| Field | Type | Required |
client_id | string | No |
client_secret | string | No |
token | string | Yes |
token_type_hint | string: one of access_token | No |
Responses
| Status | Content |
200 | application/json |
400 | application/json |
401 | application/json |
429 | application/json |
503 | application/json |
Response 200 body
| Field | Type | Required |
active | boolean | Yes |
client_id | string | No |
exp | integer (int64) | No |
organization_id | string | No |
scope | string | No |
sid | string | No |
sub | string | No |
Response 400 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 401 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 429 body
| Field | Type | Required |
error | object | No |
error.code | string | No |
error.correlation_id | string | No |
error.message | string | No |
Response 503 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
POST /oauth2/revoke
Token revocation (RFC 7009)
Authentication: client secret (HTTP Basic)
Request body: application/x-www-form-urlencoded (required)
| Field | Type | Required |
client_id | string | No |
client_secret | string | No |
token | string | Yes |
token_type_hint | string: one of access_token | No |
Responses
| Status | Content |
200 | No body |
400 | application/json |
401 | application/json |
429 | application/json |
503 | application/json |
Response 400 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 401 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 429 body
| Field | Type | Required |
error | object | No |
error.code | string | No |
error.correlation_id | string | No |
error.message | string | No |
Response 503 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
GET /userinfo
End-user claims for a validated access token
Authentication: Bearer access token (Authorization: Bearer <token>)
Responses
| Status | Content |
200 | application/json |
401 | application/json |
500 | application/json |
503 | application/json |
Response 200 body
| Field | Type | Required |
email | string | No |
email_verified | boolean | No |
organization_id | string | Yes |
sub | string | Yes |
Response 401 body
| Field | Type | Required |
error | string | Yes |
Response 500 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
Response 503 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
POST /userinfo
End-user claims for a validated access token (POST flavor)
Authentication: Bearer access token (Authorization: Bearer <token>)
Responses
| Status | Content |
200 | application/json |
401 | No body |
500 | No body |
503 | No body |
Response 200 body
| Field | Type | Required |
email | string | No |
email_verified | boolean | No |
organization_id | string | Yes |
sub | string | Yes |
GET /api/v1/me/memberships
List the token subject memberships (RP read)
Authentication: Bearer access token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required |
page | query | integer | No |
page_size | query | integer | No |
X-Correlation-ID | header | string | No |
Responses
Response 401 body
| Field | Type | Required |
error | string | Yes |
Response 503 body
| Field | Type | Required |
error | string | Yes |
error_description | string | No |
GET /logout
RP-initiated logout (end_session_endpoint, HTML surface)
Parameters
| Name | In | Type | Required |
id_token_hint | query | string | Yes |
post_logout_redirect_uri | query | string (uri) | No |
client_id | query | string | No |
state | query | string | No |
Responses
| Status | Content |
200 | text/html |
302 | No body |
400 | text/html |
500 | text/html |
503 | text/html |
POST /logout
RP-initiated logout (POST flavor)
Request body: application/x-www-form-urlencoded (required)
| Field | Type | Required |
client_id | string | No |
id_token_hint | string | Yes |
post_logout_redirect_uri | string (uri) | No |
state | string | No |
Responses
| Status | Content |
200 | No body |
302 | No body |
400 | No body |
500 | No body |
503 | No body |
Schemas
DiscoveryDocument
| Field | Type | Required |
acr_values_supported | array of string | No |
authorization_endpoint | string (uri) | Yes |
backchannel_logout_session_supported | boolean: one of true | No |
backchannel_logout_supported | boolean: one of true | Yes |
claims_supported | array of string | No |
code_challenge_methods_supported | array of string: one of S256 | Yes |
end_session_endpoint | string (uri) | Yes |
grant_types_supported | array of string: one of authorization_code | Yes |
id_token_signing_alg_values_supported | array of string: one of RS256 | Yes |
introspection_endpoint | string (uri) | Yes |
issuer | string (uri) | Yes |
jwks_uri | string (uri) | Yes |
prompt_values_supported | array of string | No |
response_types_supported | array of string: one of code | Yes |
revocation_endpoint | string (uri) | Yes |
subject_types_supported | array of string: one of public | Yes |
token_endpoint | string (uri) | Yes |
userinfo_endpoint | string (uri) | Yes |
ErrorDetail
| Field | Type | Required |
code | string | Yes |
field | string | Yes |
message | string | Yes |
ErrorResponse
| Field | Type | Required |
error | object | Yes |
error.code | string: one of VALIDATION_ERROR, BAD_REQUEST, UNAUTHORIZED, FORBIDDEN, NOT_FOUND, CONFLICT, UNPROCESSABLE, RATE_LIMITED, INTERNAL_ERROR | Yes |
error.correlation_id | string | Yes |
error.details | array of ErrorDetail | No |
error.message | string | Yes |
error.timestamp | string (date-time) | Yes |
JWK
| Field | Type | Required |
alg | string: one of RS256 | Yes |
e | string | Yes |
kid | string | Yes |
kty | string: one of RSA | Yes |
n | string | Yes |
use | string: one of sig | Yes |
JWKSet
| Field | Type | Required |
keys | array of JWK | Yes |
MeMembershipsList
| Field | Type | Required |
data | array of object | Yes |
data[].membership_id | string (uuid) | Yes |
data[].org_id | string (uuid) | Yes |
data[].org_name | string | Yes |
data[].org_slug | string | Yes |
data[].org_status | string: one of active, deleted | Yes |
data[].status | string: one of active, suspended | Yes |
pagination | object | Yes |
pagination.has_next | boolean | Yes |
pagination.has_previous | boolean | Yes |
pagination.page | integer | Yes |
pagination.page_size | integer | Yes |
pagination.total_items | integer | Yes |
pagination.total_pages | integer | Yes |