Drupal is a registered trademark of Dries Buytaert
Search API Solr 4.4.0 Minor update available for module search_api_solr (4.4.0). Page Manager 8.x-4.0 Major update available for module page_manager (8.x-4.0). Trash 3.1.0-beta2 New beta version released for module trash (3.1.0-beta2). Commerce AutoSKU 3.0.1 Minor update available for module commerce_autosku (3.0.1). Custom Field 4.0.10 Minor update available for module custom_field (4.0.10). Alternative login ID & display names 2.0.12 Minor update available for module alt_login (2.0.12). EntityReference UUID 3.0.1 Minor update available for module entity_reference_uuid (3.0.1). LocalGov Publications Importer 1.1.1 Minor update available for module localgov_publications_importer (1.1.1). Configuration Override Warn 8.x-1.6 Module config_override_warn updated after 10 months of inactivity (8.x-1.6). Table Alternate Rows Module table_altrow crossed 1,000 active installs.

This module adds OAuth 2.0 capabilities to the SSO Connector, specifically supporting the secure Authorization Code flow with PKCE. It allows Drupal to act as an OAuth client for modern single sign-on architectures, integrating with existing SSO Connector features and optionally with the simple_oauth module.

Turns an SSO Connector Identity Provider into a standards-based OAuth 2.0 Authorization Server / OpenID Provider. External applications obtain an authorization code from a CSRF-protected consent form, exchange it at the token endpoint for an RS256 access token (and an id_token when the openid scope is granted), and read scope-gated claims from the userinfo endpoint. Tokens are signed with the RS256 keypair managed by SSO Connector core, and the public key is published as a JWKS document.

Features

  • Authorization Code grant with mandatory PKCE (S256) for public clients.
  • CSRF-protected consent form — no silent auto-approval.
  • Token endpoint (authorization_code grant); other grant types are rejected.
  • Client authentication: constant-time secret verification for confidential clients, PKCE for public clients.
  • Single-use, atomically-consumed authorization codes.
  • Audience-bound RS256 access tokens carrying only minimal claims (sub, token_use, scope).
  • OpenID Connect id_token (RS256, nonce-bound) when openid is requested.
  • Scope-gated UserInfo endpoint.
  • JWKS endpoint and OpenID Connect discovery document.
  • Client definitions via the optional Consumers entity, or via module configuration.

Requirements

  • Drupal core ^11.2 || ^12
  • SSO Connector ^1.0 (provides the RS256 keypair)
  • Optional: Consumers for entity-managed OAuth clients

Installation

composer require drupal/sso_connector_oauth
drush en sso_connector_oauth

Part of the SSO Connector bundle

Requires SSO Connector (core). See the core project for the full suite and the bundle architecture document.

Activity

Total releases
3
First release
Apr 2026
Latest release
1 week ago
Releases (12 mo)
3 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.0.1 Stable Jul 21, 2026
1.0.0 Stable Jul 18, 2026
1.0.0-beta1 Pre-release Apr 26, 2026