OIDC 2.0 / OAuth 2.0Inter-Service Bridge v1Universal CORS
API Documentation
Official API reference and OIDC discovery documentation for clouburstlab identity provider.
Building with AI Agents or LLMs?
Ingest raw markdown docs directly via our machine endpoint or reference our standardized LLM profile.
Quick Links
GETOAuth / OIDC
OIDC Discovery
Returns the OpenID Connect discovery document containing issuer, endpoints, and supported scopes/claims.
/.well-known/openid-configuration
Example Request
curl -X GET "https://auth.clouburstlab.com/.well-known/openid-configuration" \
-H "Accept: application/json"
Response
{
"issuer": "https://auth.clouburstlab.com",
"authorization_endpoint": "https://auth.clouburstlab.com/signin",
"token_endpoint": "https://auth.clouburstlab.com/api/sso/v1/token",
"userinfo_endpoint": "https://auth.clouburstlab.com/api/sso/v1/userinfo",
"jwks_uri": "https://auth.clouburstlab.com/api/sso/v1/jwks.json",
"response_types_supported": ["code"],
"grant_types_supported": ["authorization_code", "refresh_token", "client_credentials"],
"id_token_signing_alg_values_supported": ["RS256"],
"code_challenge_methods_supported": ["S256"]
}
GETOAuth / OIDC
Authorization Endpoint
Initiates the OAuth 2.0 Authorization Code flow with user consent and PKCE validation.
/signin
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| client_id | string | query | Required | Your application's Client ID. |
| redirect_uri | string | query | Required | Where to redirect the user after auth. |
| response_type | string | query | Required | Must be 'code'. |
| scope | string | query | Optional | Space-separated scopes (e.g., 'openid profile email'). |
| state | string | query | Required | Opaque value for maintaining state to mitigate CSRF. |
| code_challenge | string | query | Required | PKCE code challenge generated from SHA-256. |
| code_challenge_method | string | query | Required | Must be 'S256'. |
Example Request
https://auth.clouburstlab.com/signin?client_id=cbl_xyz&redirect_uri=https%3A%2F%2Fyourapp.com%2Fcallback&response_type=code&scope=openid%20profile%20email&state=xyz123&code_challenge=E9Mel-2VzpFloWfKxIWDZaTuedIFWhGLE-XuW11fYn4&code_challenge_method=S256
Response
HTTP/1.1 302 Found
Location: https://yourapp.com/callback?code=eyJhbGciOiJIUzI1Ni...&state=xyz123
POSTOAuth / OIDC
Token Endpoint
Exchanges an authorization code, refresh token, or client credentials for access tokens.
/api/sso/v1/token
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| grant_type | string | body | Required | 'authorization_code', 'refresh_token', or 'client_credentials'. |
| client_id | string | body | Required | Your application's Client ID. |
| client_secret | string | body | Optional | Your application's Client Secret (for confidential clients or client_credentials). |
| code | string | body | Optional | The authorization code (required for authorization_code flow). |
| redirect_uri | string | body | Optional | Must match the original redirect URI (for authorization_code). |
| code_verifier | string | body | Optional | PKCE code verifier (required if PKCE was used during authorization). |
| refresh_token | string | body | Optional | The refresh token to rotate (for refresh_token grant). |
| scope | string | body | Optional | Requested scope(s) for the token. |
Example Request
# 1. Authorization Code Exchange
curl -X POST "https://auth.clouburstlab.com/api/sso/v1/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code&code=YOUR_CODE&redirect_uri=YOUR_URI&client_id=YOUR_ID&client_secret=YOUR_SECRET&code_verifier=YOUR_PKCE_VERIFIER"
# 2. Machine-to-Machine Client Credentials
curl -X POST "https://auth.clouburstlab.com/api/sso/v1/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&client_id=YOUR_ID&client_secret=YOUR_SECRET&scope=internal_service"
Response
{
"access_token": "eyJhbGciOiJIUzI1Ni...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "eyJhbGciOiJIUzI1Ni...",
"id_token": "eyJhbGciOiJSUzI1Ni...",
"scope": "openid profile email"
}
GETOAuth / OIDC
UserInfo Endpoint
Retrieves claims about the authenticated end-user based on granted scopes.
/api/sso/v1/userinfo
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| Authorization | header | header | Required | Bearer token containing the access token. |
Example Request
curl -X GET "https://auth.clouburstlab.com/api/sso/v1/userinfo" \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN"
Response
{
"sub": "cm0a1b2c3d4e5f6g7h8i9j0k",
"name": "Shawkath Ali",
"given_name": "Shawkath",
"family_name": "Ali",
"preferred_username": "shawkath",
"email": "shawkath646@gmail.com",
"email_verified": true,
"picture": "https://lh3.googleusercontent.com/a/...",
"updated_at": 1727400000
}
GETOAuth / OIDC
JWKS Endpoint
Returns the JSON Web Key Set (RS256 public keys) used to sign and verify ID tokens.
/api/sso/v1/jwks.json
Example Request
curl -X GET "https://auth.clouburstlab.com/api/sso/v1/jwks.json"
Response
{
"keys": [
{
"kty": "RSA",
"use": "sig",
"alg": "RS256",
"kid": "clou_68a9b2...",
"n": "u5K7w...p9L",
"e": "AQAB"
}
]
}
POSTOAuth / OIDC
Token Revocation Endpoint
Revokes an active access or refresh token according to RFC 7009.
/api/sso/v1/revoke
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| token | string | body | Required | The token you want to revoke. |
| client_id | string | body | Optional | Your application's Client ID. |
| client_secret | string | body | Optional | Your application's Client Secret. |
| token_type_hint | string | body | Optional | Optional hint ('access_token' or 'refresh_token'). |
Example Request
curl -X POST "https://auth.clouburstlab.com/api/sso/v1/revoke" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "token=YOUR_ACCESS_OR_REFRESH_TOKEN"
Response
HTTP/1.1 200 OK
GETInter-Service Bridge
Inter-Service User Session Bridge
Verifies active user session from cross-subdomain cookies (*.clouburstlab.com) and returns scoped profile data.
/api/inter-services/v1/user-session
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| Authorization | header | header | Required | App Bearer token (obtained via client_credentials). |
| Cookie | header | header | Optional | User session cookie ('session_token') automatically forwarded with credentials: 'include'. |
| scope | string | query | Optional | Comma-separated projection filter (e.g. 'id,firstname,lastname,email,avatar'). |
| user_id | string | query | Optional | Optional user ID for machine-to-machine server calls without cookies. |
Example Request
# 1. Browser Cross-Subdomain Call (*.clouburstlab.com)
fetch("https://auth.clouburstlab.com/api/inter-services/v1/user-session?scope=id,firstname,lastname,email,avatar", {
credentials: "include",
headers: { "Authorization": "Bearer " + appToken }
});
# 2. Server-to-Server cURL with User Identifier
curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/user-session?user_id=cm0a1b2c3...&scope=id,firstname,lastname,email" \
-H "Authorization: Bearer YOUR_APP_TOKEN"
Response
{
"authenticated": true,
"user": {
"id": "cm0a1b2c3d4e5f6g7h8i9j0k",
"username": "shawkath",
"first_name": "Shawkath",
"last_name": "Ali",
"email": "shawkath646@gmail.com",
"email_verified": true,
"avatar": "https://lh3.googleusercontent.com/a/..."
},
"scopes": ["id", "firstname", "lastname", "email"]
}
GETInter-Service Bridge
Connected Cloud Drives & Credentials
Returns decrypted OAuth credentials for the user's connected drives (Google Drive, OneDrive, Dropbox).
/api/inter-services/v1/connected-drives
Parameters
| Parameter | Type | In | Requirement | Description |
|---|---|---|---|---|
| Authorization | header | header | Required | App Bearer token (obtained via client_credentials). |
| Cookie | header | header | Optional | User session cookie ('session_token'). |
| provider | string | query | Optional | Optional filter: 'google_drive', 'onedrive', or 'dropbox'. |
| refresh | boolean | query | Optional | Optional boolean ('true') to proactively refresh expired access tokens. |
Example Request
# Retrieve decrypted Google Drive, OneDrive, or Dropbox credentials
curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/connected-drives?provider=google_drive&refresh=true" \
-H "Authorization: Bearer YOUR_APP_TOKEN" \
-H "Cookie: session_token=YOUR_SESSION_TOKEN"
Response
{
"success": true,
"user_id": "cm0a1b2c3d4e5f6g7h8i9j0k",
"count": 1,
"drives": [
{
"id": "acc_gdrive_123",
"provider": "google_drive",
"provider_user_id": "1083948572019",
"access_token": "ya29.a0AfH6SMBx...",
"refresh_token": "1//04_AbCdEf...",
"expires_at": 1727400000,
"expires_in": 3540,
"is_expired": false,
"created_on": "2026-09-27T02:00:00.000Z"
}
]
}
GETInter-Service Bridge
AI & Agent Machine Docs
Returns comprehensive, AI-friendly API documentation in pure Markdown format for automated agents.
/api/inter-services/v1/docs
Example Request
curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/docs" \
-H "Accept: text/markdown"
Response
# ClouAuth Inter-Service Bridge API Reference (v1)
> Complete raw markdown document optimized for AI agents & LLMs...