Kontyra Auth & Identity Platform
The definitive architectural manual for Kontyra Auth: OpenID Connect (OIDC) discovery, OAuth 2.0 Authorization Code flows with PKCE, WebAuthn biometric Passkeys, and RS256 token verification.
1. Overview & Universal SSO
Kontyra Auth (auth.kontyra.name.ng) is the central identity provider (IdP) for the Kontyra ecosystem. A single session created here seamlessly authenticates users across DevOS, VUX, VyntaJobs, and Kontyra Console without repeated credential prompts.
Hardware-backed biometric passkey authentication propagating to all edge applications
User triggers sign-in on auth.kontyra.name.ng via Touch ID, Face ID, or Windows Hello.
Private key inside device hardware signs random challenge; public signature sent to Kontyra Auth.
Issues cryptographically signed JSON Web Token with user claims, organizations, and tier metadata.
Shared session automatically recognized across DevOS IDE, Console, VyntaJobs, and API Gateway.
2. RFC 8414 OIDC Discovery Document
Third-party clients and microservices discover Kontyra's authentication capabilities via the standard OpenID Connect configuration endpoint:
{
"issuer": "https://auth.kontyra.name.ng",
"authorization_endpoint": "https://auth.kontyra.name.ng/oauth/authorize",
"token_endpoint": "https://api.kontyra.name.ng/v1/auth/token",
"userinfo_endpoint": "https://api.kontyra.name.ng/v1/auth/userinfo",
"jwks_uri": "https://auth.kontyra.name.ng/.well-known/jwks.json",
"response_types_supported": ["code"],
"subject_types_supported": ["public"],
"id_token_signing_alg_values_supported": ["RS256"],
"scopes_supported": ["openid", "profile", "email", "kontyra:projects", "kontyra:orgs"],
"token_endpoint_auth_methods_supported": ["client_secret_post", "client_secret_basic", "none"],
"code_challenge_methods_supported": ["S256"]
}3. OAuth 2.0 Authorization Code + PKCE
For browser single-page applications and native CLI tools (such as @kontyra/devos), Auth enforces Proof Key for Code Exchange (PKCE) to prevent code interception attacks:
# Redirect user to authorization endpoint with S256 code challenge:
https://auth.kontyra.name.ng/oauth/authorize?
response_type=code
&client_id=knt_client_82910a
&redirect_uri=https%3A%2F%2Fmyapp.com%2Fcallback
&scope=openid%20profile%20email
&code_challenge=E9Melhoa2OwvFrGMTJguCH5rtG6470-WNgMonXOjjZY
&code_challenge_method=S256curl -X POST https://api.kontyra.name.ng/v1/auth/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code" \
-d "client_id=knt_client_82910a" \
-d "code=knt_code_4b891a" \
-d "redirect_uri=https://myapp.com/callback" \
-d "code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"4. WebAuthn & FIDO2 Passkeys
Kontyra replaces vulnerable passwords with WebAuthn credentials. Users authenticate via local device biometrics (Apple Touch ID / Face ID, Windows Hello, or YubiKeys).
Passkey signatures are cryptographically bound to kontyra.name.ng and cannot be intercepted by spoofed domains.
Private keys never leave the user's Secure Enclave; the server only validates public key signatures.
5. JWT Token Claims & JWKS Verification
Access tokens issued by Kontyra Auth are formatted as RS256-signed JSON Web Tokens:
{
"iss": "https://auth.kontyra.name.ng",
"sub": "usr_98a27b1c",
"aud": "https://api.kontyra.name.ng",
"exp": 1790938400,
"iat": 1790852000,
"email": "alex@kontyra.name.ng",
"email_verified": true,
"name": "Alex Rivera",
"tier": "pro",
"orgs": [
{ "id": "org_98f12a", "role": "owner" }
]
}6. Token Refresh & Session Revocation
Refresh tokens are single-use rotated. When a user logs out or terminates a session remotely, an immediate webhook event (user.logout) is broadcast, blacklisting all derived session tokens.
7. Identity REST API Reference
Returns OpenID Connect provider configuration metadata.
Exchanges authorization code for access and refresh JWTs.
OIDC UserInfo endpoint returning verified claims (sub, email, username, tier).
Immediately invalidates an active session token or refresh token.