OIDC 2.0 / OAuth 2.0Inter-Service Bridge v1Universal CORS

API Documentation

Official API reference and OIDC discovery documentation for clouburstlab identity provider.

Building with AI Agents or LLMs?

Ingest raw markdown docs directly via our machine endpoint or reference our standardized LLM profile.

GETOAuth / OIDC
OIDC Discovery
Returns the OpenID Connect discovery document containing issuer, endpoints, and supported scopes/claims.
/.well-known/openid-configuration

Example Request

curl -X GET "https://auth.clouburstlab.com/.well-known/openid-configuration" \ -H "Accept: application/json"

Response

{ "issuer": "https://auth.clouburstlab.com", "authorization_endpoint": "https://auth.clouburstlab.com/signin", "token_endpoint": "https://auth.clouburstlab.com/api/sso/v1/token", "userinfo_endpoint": "https://auth.clouburstlab.com/api/sso/v1/userinfo", "jwks_uri": "https://auth.clouburstlab.com/api/sso/v1/jwks.json", "response_types_supported": ["code"], "grant_types_supported": ["authorization_code", "refresh_token", "client_credentials"], "id_token_signing_alg_values_supported": ["RS256"], "code_challenge_methods_supported": ["S256"] }
GETOAuth / OIDC
Authorization Endpoint
Initiates the OAuth 2.0 Authorization Code flow with user consent and PKCE validation.
/signin

Parameters

ParameterTypeInRequirementDescription
client_idstringqueryRequiredYour application's Client ID.
redirect_uristringqueryRequiredWhere to redirect the user after auth.
response_typestringqueryRequiredMust be 'code'.
scopestringqueryOptionalSpace-separated scopes (e.g., 'openid profile email').
statestringqueryRequiredOpaque value for maintaining state to mitigate CSRF.
code_challengestringqueryRequiredPKCE code challenge generated from SHA-256.
code_challenge_methodstringqueryRequiredMust be 'S256'.

Example Request

https://auth.clouburstlab.com/signin?client_id=cbl_xyz&redirect_uri=https%3A%2F%2Fyourapp.com%2Fcallback&response_type=code&scope=openid%20profile%20email&state=xyz123&code_challenge=E9Mel-2VzpFloWfKxIWDZaTuedIFWhGLE-XuW11fYn4&code_challenge_method=S256

Response

HTTP/1.1 302 Found Location: https://yourapp.com/callback?code=eyJhbGciOiJIUzI1Ni...&state=xyz123
POSTOAuth / OIDC
Token Endpoint
Exchanges an authorization code, refresh token, or client credentials for access tokens.
/api/sso/v1/token

Parameters

ParameterTypeInRequirementDescription
grant_typestringbodyRequired'authorization_code', 'refresh_token', or 'client_credentials'.
client_idstringbodyRequiredYour application's Client ID.
client_secretstringbodyOptionalYour application's Client Secret (for confidential clients or client_credentials).
codestringbodyOptionalThe authorization code (required for authorization_code flow).
redirect_uristringbodyOptionalMust match the original redirect URI (for authorization_code).
code_verifierstringbodyOptionalPKCE code verifier (required if PKCE was used during authorization).
refresh_tokenstringbodyOptionalThe refresh token to rotate (for refresh_token grant).
scopestringbodyOptionalRequested scope(s) for the token.

Example Request

# 1. Authorization Code Exchange curl -X POST "https://auth.clouburstlab.com/api/sso/v1/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=authorization_code&code=YOUR_CODE&redirect_uri=YOUR_URI&client_id=YOUR_ID&client_secret=YOUR_SECRET&code_verifier=YOUR_PKCE_VERIFIER" # 2. Machine-to-Machine Client Credentials curl -X POST "https://auth.clouburstlab.com/api/sso/v1/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=client_credentials&client_id=YOUR_ID&client_secret=YOUR_SECRET&scope=internal_service"

Response

{ "access_token": "eyJhbGciOiJIUzI1Ni...", "token_type": "Bearer", "expires_in": 3600, "refresh_token": "eyJhbGciOiJIUzI1Ni...", "id_token": "eyJhbGciOiJSUzI1Ni...", "scope": "openid profile email" }
GETOAuth / OIDC
UserInfo Endpoint
Retrieves claims about the authenticated end-user based on granted scopes.
/api/sso/v1/userinfo

Parameters

ParameterTypeInRequirementDescription
AuthorizationheaderheaderRequiredBearer token containing the access token.

Example Request

curl -X GET "https://auth.clouburstlab.com/api/sso/v1/userinfo" \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN"

Response

{ "sub": "cm0a1b2c3d4e5f6g7h8i9j0k", "name": "Shawkath Ali", "given_name": "Shawkath", "family_name": "Ali", "preferred_username": "shawkath", "email": "shawkath646@gmail.com", "email_verified": true, "picture": "https://lh3.googleusercontent.com/a/...", "updated_at": 1727400000 }
GETOAuth / OIDC
JWKS Endpoint
Returns the JSON Web Key Set (RS256 public keys) used to sign and verify ID tokens.
/api/sso/v1/jwks.json

Example Request

curl -X GET "https://auth.clouburstlab.com/api/sso/v1/jwks.json"

Response

{ "keys": [ { "kty": "RSA", "use": "sig", "alg": "RS256", "kid": "clou_68a9b2...", "n": "u5K7w...p9L", "e": "AQAB" } ] }
POSTOAuth / OIDC
Token Revocation Endpoint
Revokes an active access or refresh token according to RFC 7009.
/api/sso/v1/revoke

Parameters

ParameterTypeInRequirementDescription
tokenstringbodyRequiredThe token you want to revoke.
client_idstringbodyOptionalYour application's Client ID.
client_secretstringbodyOptionalYour application's Client Secret.
token_type_hintstringbodyOptionalOptional hint ('access_token' or 'refresh_token').

Example Request

curl -X POST "https://auth.clouburstlab.com/api/sso/v1/revoke" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "token=YOUR_ACCESS_OR_REFRESH_TOKEN"

Response

HTTP/1.1 200 OK
GETInter-Service Bridge
Inter-Service User Session Bridge
Verifies active user session from cross-subdomain cookies (*.clouburstlab.com) and returns scoped profile data.
/api/inter-services/v1/user-session

Parameters

ParameterTypeInRequirementDescription
AuthorizationheaderheaderRequiredApp Bearer token (obtained via client_credentials).
CookieheaderheaderOptionalUser session cookie ('session_token') automatically forwarded with credentials: 'include'.
scopestringqueryOptionalComma-separated projection filter (e.g. 'id,firstname,lastname,email,avatar').
user_idstringqueryOptionalOptional user ID for machine-to-machine server calls without cookies.

Example Request

# 1. Browser Cross-Subdomain Call (*.clouburstlab.com) fetch("https://auth.clouburstlab.com/api/inter-services/v1/user-session?scope=id,firstname,lastname,email,avatar", { credentials: "include", headers: { "Authorization": "Bearer " + appToken } }); # 2. Server-to-Server cURL with User Identifier curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/user-session?user_id=cm0a1b2c3...&scope=id,firstname,lastname,email" \ -H "Authorization: Bearer YOUR_APP_TOKEN"

Response

{ "authenticated": true, "user": { "id": "cm0a1b2c3d4e5f6g7h8i9j0k", "username": "shawkath", "first_name": "Shawkath", "last_name": "Ali", "email": "shawkath646@gmail.com", "email_verified": true, "avatar": "https://lh3.googleusercontent.com/a/..." }, "scopes": ["id", "firstname", "lastname", "email"] }
GETInter-Service Bridge
Connected Cloud Drives & Credentials
Returns decrypted OAuth credentials for the user's connected drives (Google Drive, OneDrive, Dropbox).
/api/inter-services/v1/connected-drives

Parameters

ParameterTypeInRequirementDescription
AuthorizationheaderheaderRequiredApp Bearer token (obtained via client_credentials).
CookieheaderheaderOptionalUser session cookie ('session_token').
providerstringqueryOptionalOptional filter: 'google_drive', 'onedrive', or 'dropbox'.
refreshbooleanqueryOptionalOptional boolean ('true') to proactively refresh expired access tokens.

Example Request

# Retrieve decrypted Google Drive, OneDrive, or Dropbox credentials curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/connected-drives?provider=google_drive&refresh=true" \ -H "Authorization: Bearer YOUR_APP_TOKEN" \ -H "Cookie: session_token=YOUR_SESSION_TOKEN"

Response

{ "success": true, "user_id": "cm0a1b2c3d4e5f6g7h8i9j0k", "count": 1, "drives": [ { "id": "acc_gdrive_123", "provider": "google_drive", "provider_user_id": "1083948572019", "access_token": "ya29.a0AfH6SMBx...", "refresh_token": "1//04_AbCdEf...", "expires_at": 1727400000, "expires_in": 3540, "is_expired": false, "created_on": "2026-09-27T02:00:00.000Z" } ] }
GETInter-Service Bridge
AI & Agent Machine Docs
Returns comprehensive, AI-friendly API documentation in pure Markdown format for automated agents.
/api/inter-services/v1/docs

Example Request

curl -X GET "https://auth.clouburstlab.com/api/inter-services/v1/docs" \ -H "Accept: text/markdown"

Response

# ClouAuth Inter-Service Bridge API Reference (v1) > Complete raw markdown document optimized for AI agents & LLMs...