Discovery
External IdP login descriptor
Public capability hint: whether IdP login is enabled, and which provider.
The SPA reads this before login to decide whether to show a "Continue with <provider>" button. Unauthenticated and secret-free — it advertises only the enabled flag and the provider name (never client secrets or endpoints).
get/auth/idp
Response
Successful Response
object required