PageSourceSearch

https://www.azuma.health/assets/js/1eb908d3.e1542a95.js

js azuma.health collected 2026-09-28 07:49:57 UTC 10,569 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkazuma_website=self.webpackChunkazuma_website||[]).push([["4198"],{9408(e,n,t){t.r(n),t.d(n,{metadata:()=>o,default:()=>l,frontMatter:()=>r,contentTitle:()=>c,toc:()=>d,assets:()=>a});var o=JSON.parse('{"id":"concepts/auth","title":"Authentication / Authorization","description":"All azuma products are backed by azuma doa for Authentication and Authorization;","source":"@site/technical-docs/concepts/auth.md","sourceDirName":"concepts","slug":"/concepts/auth","permalink":"/tech/concepts/auth","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"sidebar_label":"Authentication / Authorization","slug":"/concepts/auth"},"sidebar":"technicalSidebar","previous":{"title":"Concepts","permalink":"/tech/concepts"},"next":{"title":"Tenant Management","permalink":"/tech/concepts/tenants"}}'),s=t(4848),i=t(8453);let r={sidebar_label:"Authentication / Authorization",slug:"/concepts/auth"},c="Authentication / Authorization",a={},d=[{value:"OAuth 2.0",id:"oauth-20",level:3},{value:"OpenID Connect (OIDC)",id:"openid-connect-oidc",level:3},{value:"Flows",id:"flows",level:2},{value:"Currently supported and ready to be used",id:"currently-supported-and-ready-to-be-used",level:3},{value:"Not yet supported",id:"not-yet-supported",level:3},{value:"Out of scope and will not be supported",id:"out-of-scope-and-will-not-be-supported",level:3},{value:"Further Information",id:"further-information",level:2}];function h(e){let n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",strong:"strong",ul:"ul",...(0,i.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"authentication--authorization",children:"Authentication / Authorization"})}),"\n",(0,s.jsxs)(n.p,{children:["All azuma products are backed by ",(0,s.jsx)(n.strong,{children:(0,s.jsx)(n.a,{href:"/tech/products/doa",children:"azuma doa"})})," for ",(0,s.jsx)(n.strong,{children:"Authentication"})," and ",(0,s.jsx)(n.strong,{children:"Authorization"}),";"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:(0,s.jsx)(n.a,{href:"/tech/products/doa",children:"azuma doa"})})," is based on the state-of-the-art, secure, and widely deployed open-source ",(0,s.jsx)(n.strong,{children:(0,s.jsx)(n.a,{href:"https://github.com/ory/hydra",children:"Ory Hydra Federation Server"})})," and provides:"]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.strong,{children:"OAuth 2.0"})}),"\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.strong,{children:"OpenID Connect (OIDC)"})}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.strong,{children:"Access Control List (ACL)"})," based authorization system"]}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:["to authenticate and authorize ",(0,s.jsx)(n.code,{children:"users"}),"."]}),"\n",(0,s.jsx)(n.h3,{id:"oauth-20",children:"OAuth 2.0"}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OAuth 2.0"})," is a standard authorization protocol that enables third-party applications to access a user's resources without requiring the user to share their credentials. It can be implemented for ",(0,s.jsx)(n.strong,{children:"user centric services"})," as well as for secure ",(0,s.jsx)(n.strong,{children:"machine-to-machine communication"}),"."]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OAuth 2.0"})," involves four main components:"]}),"\n",(0,s.jsxs)(n.ol,{children:["\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.code,{children:"resource owner"}),": The entity that owns the resources, such as a ",(0,s.jsx)(n.code,{children:"user"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.code,{children:"client"}),": The application that wants to access the resources on behalf of the ",(0,s.jsx)(n.code,{children:"resource owner"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.code,{children:"authorization server"}),": The server that authenticates the ",(0,s.jsx)(n.code,{children:"resource owner"})," and issues an access token to the ",(0,s.jsx)(n.code,{children:"client"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:[(0,s.jsx)(n.code,{children:"resource server"}),": The server that holds the protected resources and accepts the access token to grant access to the ",(0,s.jsx)(n.code,{children:"client"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OAuth 2.0"})," works by the ",(0,s.jsx)(n.code,{children:"client"})," requesting authorization from the ",(0,s.jsx)(n.code,{children:"resource owner"})," to access their resources."]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["The ",(0,s.jsx)(n.code,{children:"resource owner"})," grants authorization to the ",(0,s.jsx)(n.code,{children:"client"})," by redirecting the ",(0,s.jsx)(n.code,{children:"client"})," to the ",(0,s.jsx)(n.code,{children:"authorization server"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:["The ",(0,s.jsx)(n.code,{children:"authorization server"})," authenticates the ",(0,s.jsx)(n.code,{children:"resource owner"})," and issues an access token to the ",(0,s.jsx)(n.code,{children:"client"}),"."]}),"\n",(0,s.jsxs)(n.li,{children:["The ",(0,s.jsx)(n.code,{children:"client"})," then uses  access token to access the protected resources on the ",(0,s.jsx)(n.code,{children:"resource server"}),"."]}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"OAuth 2.0"})," also supports the use of refresh tokens, which enable the ",(0,s.jsx)(n.code,{children:"client"})," to obtain a new access token without requiring the ",(0,s.jsx)(n.code,{children:"resource owner"})," to re-authorize the ",(0,s.jsx)(n.code,{children:"client"}),". This helps to minimize the number of times the ",(0,s.jsx)(n.code,{children:"resource owner"})," is required to authenticate, making the authentication process more convenient for the ",(0,s.jsx)(n.code,{children:"user"}),"."]}),"\n",(0,s.jsx)(n.h3,{id:"openid-connect-oidc",children:"OpenID Connect (OIDC)"}),"\n",(0,s.jsxs)(n.p,{children:["OpenlD Connect (",(0,s.jsx)(n.strong,{children:"OIDC"}),") is an authentication protocol built on top of the OAuth2 framework. It enables clients to verify the identity of end-users based on the authentication performed by an ",(0,s.jsx)(n.code,{children:"authorization server"}),", as well as obtain basic profile information about the ",(0,s.jsx)(n.code,{children:"user"}),"."]}),"\n",(0,s.jsxs)(n.p,{children:["While ",(0,s.jsx)(n.strong,{children:"OAuth 2.0"})," provides a mechanism for a client application to obtain access to protected resources on behalf of a ",(0,s.jsx)(n.code,{children:"user"}),", it does not provide a standard way to authenticate the ",(0,s.jsx)(n.code,{children:"user"}),". ",(0,s.jsx)(n.strong,{children:"OIDC"})," addresses this limitation by introducing an ",(0,s.jsx)(n.code,{children:"ID Token"}),", which is a JSON Web Token (JWT) that contains information about the ",(0,s.jsx)(n.code,{children:"user"})," and their authentication status."]}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsxs)(n.li,{children:["When a ",(0,s.jsx)(n.code,{children:"user"})," authenticates with an ",(0,s.jsx)(n.strong,{children:"OIDC"})," provider, the provider issues an ",(0,s.jsx)(n.code,{children:"ID Token"}
1)," that contains a set of claims about the ",(0,s.jsx)(n.code,{children:"user"}),", such as their name, email address, and unique identifier."]}),"\n",(0,s.jsxs)(n.li,{children:["The client application can use this ",(0,s.jsx)(n.code,{children:"ID Token"})," to authenticate the ",(0,s.jsx)(n.code,{children:"user"})," and obtain additional information about them from the OIDC provider's userinfo endpoint."]}),"\n"]}),"\n",(0,s.jsxs)(n.p,{children:["In addition to the ",(0,s.jsx)(n.code,{children:"ID Token"}),", ",(0,s.jsx)(n.strong,{children:"OIDC"})," also defines a standard set of scopes and endpoints for obtaining additional information about the ",(0,s.jsx)(n.code,{children:"user"}),", such as their profile and email address. This makes it easier for client applications to obtain the information they need to provide a personalized user experience, while also providing a standardized way to secure and authenticate user information."]}),"\n",(0,s.jsx)(n.admonition,{title:"Note",type:"note",children:(0,s.jsxs)(n.p,{children:["You can use ",(0,s.jsx)(n.strong,{children:(0,s.jsx)(n.a,{href:"/tech/products/doa",children:"azuma doa"})})," if you want to authenticate your ",(0,s.jsx)(n.code,{children:"users"})," with their social sign-in accounts from providers like Microsoft or Google, or an existing single sign-on (SSO). It supports login via any ",(0,s.jsx)(n.strong,{children:"OIDC"}),"-compliant provider."]})}),"\n",(0,s.jsx)(n.h2,{id:"flows",children:"Flows"}),"\n",(0,s.jsx)(n.h3,{id:"currently-supported-and-ready-to-be-used",children:"Currently supported and ready to be used"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:"Authorization Code Flow"}),"\n",(0,s.jsx)(n.li,{children:"Authorization Code Flow (with PKCE)"}),"\n",(0,s.jsx)(n.li,{children:"Client Credentials Flow"}),"\n"]}),"\n",(0,s.jsx)(n.h3,{id:"not-yet-supported",children:"Not yet supported"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:"Device Authorization Flow"}),"\n"]}),"\n",(0,s.jsx)(n.h3,{id:"out-of-scope-and-will-not-be-supported",children:"Out of scope and will not be supported"}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:"Implicit Flow (please use Authorization Code Flow (with PKCE) instead)"}),"\n",(0,s.jsx)(n.li,{children:"Resource Owner Password Flow (please use Authorization Code Flow (with PKCE) instead)"}),"\n"]}),"\n",(0,s.jsx)(n.h2,{id:"further-information",children:"Further Information"}),"\n",(0,s.jsxs)(n.p,{children:["For information regarding ",(0,s.jsx)(n.code,{children:"roles"}),", ",(0,s.jsx)(n.code,{children:"permissions"})," and ",(0,s.jsx)(n.code,{children:"scopes"})," please check the ",(0,s.jsx)(n.strong,{children:(0,s.jsx)(n.a,{href:"/tech/products/doa",children:"azuma doa documentation"})}),"."]})]})}function l(e={}){let{wrapper:n}={...(0,i.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(h,{...e})}):h(e)}},8453(e,n,t){t.d(n,{R:()=>r,x:()=>c});var o=t(6540);let s={},i=o.createContext(s);function r(e){let n=o.useContext(i);return o.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function c(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),o.createElement(i.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.