Difference Between Well-Known OpenID Configuration and OAuth Authorization Server Endpoints in Okta
Last Updated:
Overview
Okta provides two similar discovery endpoints for application configuration: /.well-known/openid-configuration and /.well-known/oauth-authorization-server.
The OpenID configuration endpoint complies with the OpenID Connect (OIDC) standard for authentication, while the OAuth authorization server endpoint complies with the OAuth 2.0 standard for authorization. Select the endpoint that matches the protocol standard expected by the application library.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OAuth 2.0
- OpenID Connect (OIDC)
Solution
The Primary Difference Between the Endpoints is the Supported Protocol Standard
These endpoints differ primarily in the specific protocol standard they support.
- OpenID Configuration
- Endpoint:
/.well-known/openid-configuration - Protocol: OpenID Connect (OIDC)
- Purpose: This endpoint complies with the OpenID Connect Discovery 1.0 standard. Clients implementing OIDC use this endpoint for authentication to verify an identity. The returned metadata includes OIDC-specific information, such as the
userinfo_endpointand supported scopes likeopenid,profile, andemail.
- Endpoint:
- OAuth Authorization Server
- Endpoint:
/.well-known/oauth-authorization-server - Protocol: OAuth 2.0
- Purpose: This endpoint complies with the OAuth 2.0 Authorization Server Metadata (RFC 8414) standard. Clients implementing pure OAuth 2.0 use this endpoint for authorization to grant access to resources. While the metadata resembles the OIDC configuration, this endpoint specifically serves OAuth clients that do not require identity assertions.
- Endpoint:
OIDC builds on top of OAuth 2.0, so the metadata from these endpoints often overlaps. Select the endpoint that matches the protocol standard expected by the application library.
How are the discovery endpoints formatted for different authorization servers?
Retrieve the metadata for the Org Authorization Server by performing a GET request to the following discovery endpoints at the root of the Okta domain.
- OIDC Discovery Endpoint:
https://<OktaDomainName>/.well-known/openid-configuration
- OAuth 2.0 Discovery Endpoint:
https://<OktaDomainName>/.well-known/oauth-authorization-server
Retrieve the metadata for a Custom Authorization Server by performing a GET request to the following discovery endpoints, replacing <authorizationServerId> with the specific alphanumeric ID or default.
- OIDC Discovery Endpoint:
https://<OktaDomainName>/oauth2/<authorizationServerId>/.well-known/openid-configuration
- OAuth 2.0 Discovery Endpoint:
https://<OktaDomainName>/oauth2/<authorizationServerId>/.well-known/oauth-authorization-server
Related References
- OAuth 2.0 Authorization Server Metadata | RFC
- OpenID Connect Discovery 1.0 | OpenID Specification
- Org Authorization Server Discovery Endpoints | Okta Developer
- Custom Authorization Server Discovery Endpoints | Okta Developer
- Get Well-Known OAuth Configuration for Custom Authorization Servers | Okta Developer
- Get Well-Known OpenID Configuration for Custom Authorization Servers | Okta Developer
- Get Well-Known OpenID Configuration for Org Authorization Server | Okta Developer
