AUTH4D-2 shared API and protocol contracts
These schemas define the wire shapes; this fragment does not enable any routes. Until an owning feature ticket implements a route, it remains unavailable/501.
Customer authentication
GET /t/{tenantId}/.well-known/openid-configurationreturnsOidcDiscoveryDocument.GET /t/{tenantId}/.well-known/jwks.jsonreturnsJwksResponsewith public RS256 keys only.GET /oauth/authorizeacceptsAuthorizationRequest:response_type=code, exactredirect_uri,state,code_challenge,code_challenge_method=S256, andscopeincludingopenid. Success redirects withcodeandstate; failures useOAuthErrorResponse.POST /oauth/tokenaccepts oneTokenRequestvariant:authorization_code,refresh_token, orurn:ietf:params:oauth:grant-type:device_code. Success returnsTokenResponse; failures useOAuthErrorResponse. Implicit and password grants are unsupported.POST /oauth/revokeacceptsTokenRevocationRequestand returns an empty success response;GET /oauth/userinforeturnsUserInfoResponsefor a valid access token with the required scopes.POST /t/{tenantId}/email/verification/startacceptsEmailVerificationStartRequest;POST /t/{tenantId}/email/verification/confirmacceptsEmailVerificationConfirmRequestand returns anIdentityProofResponsereceipt. Generic start responses prevent account enumeration.GET /t/{tenantId}/identity/discord/startacceptsDiscordAuthorizationStartRequest; the provider returns to/t/{tenantId}/identity/discord/callbackwithDiscordCallbackQuery. Callback state is one-time and browser-flow-bound.POST /t/{tenantId}/guestacceptsGuestCreateRequestand returnsGuestCreateResponse;POST /t/{tenantId}/guest/upgradeacceptsGuestUpgradeRequestand returnsGuestUpgradeResponse. The upgrade proof must belong to the same tenant, client, flow, purpose, and guest user.POST /device/authorizationacceptsDeviceAuthorizationRequestand returnsDeviceAuthorizationResponse;POST /device/approvalacceptsDeviceApprovalRequestand returnsDeviceApprovalResponse. Native clients redeem through the device-code token request.
Management and console
GET /management/tenantsreturnsManagementTenantListResponse;POST /management/tenantsacceptsCreateTenantRequestand returnsManagementTenantResponse.GET /management/tenants/{tenantId}/clientsreturnsManagementClientListResponse;POST /management/tenants/{tenantId}/clientsacceptsCreateClientRequestand returnsCreateClientResponse. A confidential client secret, when returned, is shown once and cannot be retrieved later.PUT /management/tenants/{tenantId}/clients/{clientId}acceptsUpdateClientRequestand returnsManagementClientResponse; list responses useManagementClientListResponse.- Every management route requires a
ManagementActorfrom the immutable control-plane realm and checks its route scope (tenant:read/write,client:read/write, etc.). Errors useManagementErrorResponse; the console browser only calls its/api/*BFF and never handles the management credential.
X-Request-Id is server-generated and stable through response/error/audit handling; inbound values
are ignored. OAuth errors remain protocol-shaped and are correlated through the response header;
management errors carry request_id in their envelope. All schemas reject unknown fields where
accepting them could blur security-sensitive policy.
See the architecture and security contracts (repository file docs/architecture/security-contracts.md) for service
ownership, storage authority, trust boundaries, default expiries, and abuse budgets.
Source: docs/api-spec/auth4d-2.md