Want people to log in to your app with their Street Art Cities account? We support OpenID Connect, so most login libraries can do this for you: give them https://streetartcities.com as the issuer, and they'll find everything else in our discovery document:
https://streetartcities.com/.well-known/openid-configurationHow it works
It's the same OAuth flow, with one or more of these scopes:
| Scope | What your app gets |
|---|---|
openid | An ID token that says who the person is. Always needed for logging in |
profile | Their name, username, profile picture and a link to their profile |
email | Their email address, and whether they've confirmed it |
You can combine them with API scopes, like openid profile collections:read.
When your request includes openid, the token response also has an id_token:
{
"access_token": "eyJhbGciOi...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "Yh1c...",
"scope": "openid profile email",
"id_token": "eyJhbGciOi..."
}The ID token
The ID token is a JWT signed with RS256. Before trusting it, check that:
- the signature matches one of the keys in our JWKS
issishttps://streetartcities.comaudis your client IDexphasn't passednoncematches the one you sent, if you sent one
Send a random nonce to the authorize page, and we'll put it in the ID token. That stops someone from replaying an old token.
{
"iss": "https://streetartcities.com",
"sub": "9b1c0e2f-…",
"aud": "YOUR_CLIENT_ID",
"exp": 1790000000,
"iat": 1789996400,
"nonce": "n-0S6_WzA2Mj",
"name": "Ada L.",
"preferred_username": "ada",
"profile": "https://streetartcities.com/@ada",
"picture": "https://…/512.jpg",
"email": "ada@example.com",
"email_verified": true
}Use sub to recognise people: it never changes, unlike their username or email address.
The userinfo endpoint
You can also get the same details with the access token:
curl https://streetartcities.com/api/oauth/userinfo \
-H "Authorization: Bearer ACCESS_TOKEN"This needs the openid scope, and only returns the details the person agreed to share.
Refreshing the access token also gives you a new ID token, with up-to-date details. See tokens.