v16

OpenAPI 3.0.3Apache 2.0raw.githubusercontent.com2026-04-0886158866.0 KB
Native SSO

Native SSO Processing

This API should be called by the implementation of a token endpoint to generate the ID token and token response that comply with OpenID Connect Native SSO for Mobile Apps 1.0 (Native SSO) when Authlete’s /auth/token response indicates action = NATIVE_SSO (after you validate the session id and verify or generate the device secret as required by the flow). The token endpoint implementation should retrieve the value of action from the response and take the following steps according to the value.

post/api/{serviceId}/nativesso

Path parameters

serviceIdstring required

A service ID.

Request body

accessTokenstring required

The value of this parameter should be: (a) the value of the jwtAccessToken parameter in a response from the /auth/token API when the value is available, or (b) the value of the accessToken parameter in the response from the /auth/token API when the jwtAccessToken parameter is not available.

refreshTokenstring

The value of this parameter should be the value of the refreshToken parameter in a response from the /auth/token API.

substring

The value that should be used as the value of the sub claim of the ID token. This parameter is optional. When omitted, the value of the subject associated with the access token is used.

claimsstring

Additional claims that should be embedded in the payload part of the ID token. The format is a JSON object. This parameter is optional.

idtHeaderParamsstring

Additional parameters that should be embedded in the JWS header of the ID token. The format is a JSON object. This parameter is optional.

idTokenAudTypestring

The type of the aud claim of the ID token being issued. Valid values of this parameter are as follows:

deviceSecretstring required

The device secret. The value of this parameter should be the value of the deviceSecret parameter in the response from the /auth/token API, if the parameter is present. Otherwise, the authorization server should generate a new device secret and specify it as the value of this parameter.

deviceSecretHashstring

The device secret hash. The specified device secret hash is included as the value of the ds_hash claim in the ID token generated by the /nativesso API. If the deviceSecretHash request parameter is omitted, the value of the deviceSecret request parameter is used to compute the hash.

Response

Native SSO processing completed successfully

resultCodestring

The code which represents the result of the API call.

resultMessagestring

A short message which explains the result of the API call.

action'OK' | 'INTERNAL_SERVER_ERROR' | 'CALLER_ERROR'

The next action that the implementation of the token endpoint should take.

responseContentstring

The response content that can be used as the message body of the token response that should be returned from the token endpoint.

idTokenstring

The issued ID token.