KontyraKontyra Docs
Identity Authority•auth.kontyra.name.ng

Kontyra Auth & Identity Platform

The definitive architectural manual for Kontyra Auth: OpenID Connect (OIDC) discovery, OAuth 2.0 Authorization Code flows with PKCE, WebAuthn biometric Passkeys, and RS256 token verification.

1. Overview & Universal SSO

Kontyra Auth (auth.kontyra.name.ng) is the central identity provider (IdP) for the Kontyra ecosystem. A single session created here seamlessly authenticates users across DevOS, VUX, VyntaJobs, and Kontyra Console without repeated credential prompts.

Universal Identity Delegation Pipeline

Hardware-backed biometric passkey authentication propagating to all edge applications

Pipeline Flow
User Device & Browser RequestClient Biometrics
auth.kontyra.name.ng

User triggers sign-in on auth.kontyra.name.ng via Touch ID, Face ID, or Windows Hello.

Hardware Secure Enclave SignFIDO2 / WebAuthn
Phishing-Resistant

Private key inside device hardware signs random challenge; public signature sent to Kontyra Auth.

RS256 JWT Token MintingIdentity Authority
Rotated JWKS Keys

Issues cryptographically signed JSON Web Token with user claims, organizations, and tier metadata.

Federated Ecosystem IngressUniversal SSO
Bearer Token Auth

Shared session automatically recognized across DevOS IDE, Console, VyntaJobs, and API Gateway.

2. RFC 8414 OIDC Discovery Document

Third-party clients and microservices discover Kontyra's authentication capabilities via the standard OpenID Connect configuration endpoint:

GET https://auth.kontyra.name.ng/.well-known/openid-configuration
.well-known/openid-configuration
{
  "issuer": "https://auth.kontyra.name.ng",
  "authorization_endpoint": "https://auth.kontyra.name.ng/oauth/authorize",
  "token_endpoint": "https://api.kontyra.name.ng/v1/auth/token",
  "userinfo_endpoint": "https://api.kontyra.name.ng/v1/auth/userinfo",
  "jwks_uri": "https://auth.kontyra.name.ng/.well-known/jwks.json",
  "response_types_supported": ["code"],
  "subject_types_supported": ["public"],
  "id_token_signing_alg_values_supported": ["RS256"],
  "scopes_supported": ["openid", "profile", "email", "kontyra:projects", "kontyra:orgs"],
  "token_endpoint_auth_methods_supported": ["client_secret_post", "client_secret_basic", "none"],
  "code_challenge_methods_supported": ["S256"]
}

3. OAuth 2.0 Authorization Code + PKCE

For browser single-page applications and native CLI tools (such as @kontyra/devos), Auth enforces Proof Key for Code Exchange (PKCE) to prevent code interception attacks:

1. Initiate Authorization
# Redirect user to authorization endpoint with S256 code challenge:
https://auth.kontyra.name.ng/oauth/authorize?
  response_type=code
  &client_id=knt_client_82910a
  &redirect_uri=https%3A%2F%2Fmyapp.com%2Fcallback
  &scope=openid%20profile%20email
  &code_challenge=E9Melhoa2OwvFrGMTJguCH5rtG6470-WNgMonXOjjZY
  &code_challenge_method=S256
2. Exchange Code for JWT via cURL
curl -X POST https://api.kontyra.name.ng/v1/auth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=authorization_code" \
  -d "client_id=knt_client_82910a" \
  -d "code=knt_code_4b891a" \
  -d "redirect_uri=https://myapp.com/callback" \
  -d "code_verifier=dBjftJeZ4CVP-mB92K27uhbUJU1p1r_wW1gFWFOEjXk"

4. WebAuthn & FIDO2 Passkeys

Kontyra replaces vulnerable passwords with WebAuthn credentials. Users authenticate via local device biometrics (Apple Touch ID / Face ID, Windows Hello, or YubiKeys).

Phishing-Resistant Origin Binding

Passkey signatures are cryptographically bound to kontyra.name.ng and cannot be intercepted by spoofed domains.

Zero Shared Secrets

Private keys never leave the user's Secure Enclave; the server only validates public key signatures.

5. JWT Token Claims & JWKS Verification

Access tokens issued by Kontyra Auth are formatted as RS256-signed JSON Web Tokens:

Decoded JWT Payload
{
  "iss": "https://auth.kontyra.name.ng",
  "sub": "usr_98a27b1c",
  "aud": "https://api.kontyra.name.ng",
  "exp": 1790938400,
  "iat": 1790852000,
  "email": "alex@kontyra.name.ng",
  "email_verified": true,
  "name": "Alex Rivera",
  "tier": "pro",
  "orgs": [
    { "id": "org_98f12a", "role": "owner" }
  ]
}

6. Token Refresh & Session Revocation

Refresh tokens are single-use rotated. When a user logs out or terminates a session remotely, an immediate webhook event (user.logout) is broadcast, blacklisting all derived session tokens.

7. Identity REST API Reference

GET/v1/auth/.well-known/openid-configuration

Returns OpenID Connect provider configuration metadata.

POST/v1/auth/token

Exchanges authorization code for access and refresh JWTs.

GET/v1/auth/userinfo

OIDC UserInfo endpoint returning verified claims (sub, email, username, tier).

POST/v1/auth/revoke

Immediately invalidates an active session token or refresh token.