<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Difference Between Well-Known OpenID Configuration and OAuth Authorization Server Endpoints in Okta

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

Okta provides two similar discovery endpoints for application configuration: /.well-known/openid-configuration and /.well-known/oauth-authorization-server.

 

The OpenID configuration endpoint complies with the OpenID Connect (OIDC) standard for authentication, while the OAuth authorization server endpoint complies with the OAuth 2.0 standard for authorization. Select the endpoint that matches the protocol standard expected by the application library.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OAuth 2.0
  • OpenID Connect (OIDC)

Solution

The Primary Difference Between the Endpoints is the Supported Protocol Standard

These endpoints differ primarily in the specific protocol standard they support.

  • OpenID Configuration
    • Endpoint: /.well-known/openid-configuration
    • Protocol: OpenID Connect (OIDC)
    • Purpose: This endpoint complies with the OpenID Connect Discovery 1.0 standard. Clients implementing OIDC use this endpoint for authentication to verify an identity. The returned metadata includes OIDC-specific information, such as the userinfo_endpoint and supported scopes like openid, profile, and email.
  • OAuth Authorization Server
    • Endpoint: /.well-known/oauth-authorization-server
    • Protocol: OAuth 2.0
    • Purpose: This endpoint complies with the OAuth 2.0 Authorization Server Metadata (RFC 8414) standard. Clients implementing pure OAuth 2.0 use this endpoint for authorization to grant access to resources. While the metadata resembles the OIDC configuration, this endpoint specifically serves OAuth clients that do not require identity assertions.

OIDC builds on top of OAuth 2.0, so the metadata from these endpoints often overlaps. Select the endpoint that matches the protocol standard expected by the application library.

 

How are the discovery endpoints formatted for different authorization servers?

Retrieve the metadata for the Org Authorization Server by performing a GET request to the following discovery endpoints at the root of the Okta domain.

  • OIDC Discovery Endpoint:
    https://<OktaDomainName>/.well-known/openid-configuration
  • OAuth 2.0 Discovery Endpoint:
    https://<OktaDomainName>/.well-known/oauth-authorization-server

 

Retrieve the metadata for a Custom Authorization Server by performing a GET request to the following discovery endpoints, replacing <authorizationServerId> with the specific alphanumeric ID or default.

  • OIDC Discovery Endpoint:
    https://<OktaDomainName>/oauth2/<authorizationServerId>/.well-known/openid-configuration
  • OAuth 2.0 Discovery Endpoint:
    https://<OktaDomainName>/oauth2/<authorizationServerId>/.well-known/oauth-authorization-server

 

Related References

Loading
Difference Between Well-Known OpenID Configuration and OAuth Authorization Server Endpoints in Okta | Okta Support