SSO Connector OAuth
This module adds OAuth 2.0 capabilities to the SSO Connector, specifically supporting the secure Authorization Code flow with PKCE. It allows Drupal to act as an OAuth client for modern single sign-on architectures, integrating with existing SSO Connector features and optionally with the simple_oauth module.
Turns an SSO Connector Identity Provider into a standards-based OAuth 2.0 Authorization Server / OpenID Provider. External applications obtain an authorization code from a CSRF-protected consent form, exchange it at the token endpoint for an RS256 access token (and an id_token when the openid scope is granted), and read scope-gated claims from the userinfo endpoint. Tokens are signed with the RS256 keypair managed by SSO Connector core, and the public key is published as a JWKS document.
Features
- Authorization Code grant with mandatory PKCE (S256) for public clients.
- CSRF-protected consent form — no silent auto-approval.
- Token endpoint (authorization_code grant); other grant types are rejected.
- Client authentication: constant-time secret verification for confidential clients, PKCE for public clients.
- Single-use, atomically-consumed authorization codes.
- Audience-bound RS256 access tokens carrying only minimal claims (
sub,token_use,scope). - OpenID Connect
id_token(RS256, nonce-bound) whenopenidis requested. - Scope-gated UserInfo endpoint.
- JWKS endpoint and OpenID Connect discovery document.
- Client definitions via the optional Consumers entity, or via module configuration.
Requirements
- Drupal core
^11.2 || ^12 - SSO Connector
^1.0(provides the RS256 keypair) - Optional: Consumers for entity-managed OAuth clients
Installation
composer require drupal/sso_connector_oauth drush en sso_connector_oauth
Part of the SSO Connector bundle
Requires SSO Connector (core). See the core project for the full suite and the bundle architecture document.