Skip to content

Models: I

  • data: list[kindgi.client.IdentityProviderConfig]

OAuth 2.0 / OIDC provider configuration registered on a tenant. clientSecretRef is a REFERENCE resolved server-side (env-var key, secrets-manager path, KMS handle) — the plaintext client secret never crosses the wire.

  • provider_id: str (providerId on the wire)
  • kind: Literal['oauth2', 'oidc']
  • client_id: str (clientId on the wire)
  • client_secret_ref: str (clientSecretRef on the wire)
  • authorization_endpoint: AnyUrl (authorizationEndpoint on the wire)
  • token_endpoint: AnyUrl (tokenEndpoint on the wire)
  • userinfo_endpoint: AnyUrl | None (userinfoEndpoint on the wire) (optional)
  • scopes: list[str]
  • allowed_redirect_uris: list[kindgi.client.AllowedRedirectUri] | None (allowedRedirectUris on the wire) (optional)
  • claim_mapping: kindgi.client.ClaimMappingSpec | None (claimMapping on the wire) (optional)
  • metadata: dict[str, Any] | None (optional)
  • root: Literal['oauth2', 'oidc']
  • data: list[kindgi.client.IdentitySessionSummary]
  • has_more: bool (hasMore on the wire)
  • next_cursor: str | None (nextCursor on the wire) (optional)

Wire-safe subset of a session. Excludes provider access-token / refresh-token — those never cross the wire, even to admins.

  • session_id: str (sessionId on the wire)
  • user_id: str (userId on the wire)
  • provider_id: str (providerId on the wire)
  • created_at: AwareDatetime (createdAt on the wire)
  • expires_at: AwareDatetime (expiresAt on the wire)
  • scopes: list[str]
  • revoked_at: AwareDatetime | None (revokedAt on the wire) (optional)