Skip to main content

Endpoints overview

This page is the authoritative reference for the public Klubero SSO endpoints used in third-party integrations. The endpoints are split into standard OpenID Connect endpoints and the service (M2M) REST API.

Core OIDC endpoints​

These are the standard OpenID Connect endpoints:

EndpointURLDescription
Discovery/.well-known/openid-configurationOpenID configuration metadata
JWKS/.well-known/jwksPublic keys for token verification
Authorization/connect/authorizeStart the OAuth flow
Token/connect/tokenExchange the code for tokens
UserInfo/connect/userinfoRetrieve the user's claims
Logout/connect/logoutEnd the user's session
Introspection/connect/introspectValidate a token
Revocation/connect/revokeRevoke a token

Discovery endpoint​

The discovery endpoint provides all the configuration needed to integrate with Klubero SSO:

curl https://your-sso-domain.com/.well-known/openid-configuration

Response:

{
"issuer": "https://your-sso-domain.com/",
"authorization_endpoint": "https://your-sso-domain.com/connect/authorize",
"token_endpoint": "https://your-sso-domain.com/connect/token",
"userinfo_endpoint": "https://your-sso-domain.com/connect/userinfo",
"end_session_endpoint": "https://your-sso-domain.com/connect/logout",
"introspection_endpoint": "https://your-sso-domain.com/connect/introspect",
"revocation_endpoint": "https://your-sso-domain.com/connect/revoke",
"jwks_uri": "https://your-sso-domain.com/.well-known/jwks",
"scopes_supported": ["openid", "profile", "email", "phone", "address", "offline_access", "api"],
"response_types_supported": ["code"],
"grant_types_supported": ["authorization_code", "refresh_token", "client_credentials"],
"code_challenge_methods_supported": ["S256", "plain"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post"]
}
note

The issuer value is derived dynamically from the host the discovery document is loaded from. Always read the actual values from the live discovery endpoint, not from this example.


Service REST API (M2M)​

In addition to OIDC, Klubero SSO provides a service REST API for management. These endpoints are intended for service-to-service (machine-to-machine) communication.

CategoryBase PathDescription
Users/api/users/*User management
Sessions/api/sessions/*Session management
Magic Link/api/magiclink/*Passwordless authentication
Two-Factor (management)/api/twofactor/{guid}/*User 2FA management
Service API authentication

The /api/* endpoints (except those explicitly anonymous) require an M2M access token obtained via the Client Credentials flow with the api scope. User tokens obtained via the Authorization Code Flow do not have access to these management endpoints. For details, see Scopes and Claims.