Web apps (server)
Use a Web app (server) client when your server receives the authorization code and keeps the client secret.
The secret can go in the request as HTTP Basic (client_secret_basic) or in the form body (client_secret_post); both work.
PKCE is required as well, and the libraries below do it for you.
The issuer is https://auth.motaware.com/, ending in a slash. Libraries that compare issuers exactly need that slash.
ASP.NET Core
Register https://your-site/signin-motaware as the redirect URL and https://your-site/signout-callback-motaware as the sign-out return URL.
// dotnet add package Microsoft.AspNetCore.Authentication.OpenIdConnect
builder.Services.AddAuthentication(options =>
{
options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = "Motaware";
})
.AddCookie()
.AddOpenIdConnect("Motaware", options =>
{
options.Authority = "https://auth.motaware.com";
options.ClientId = builder.Configuration["Motaware:ClientId"];
options.ClientSecret = builder.Configuration["Motaware:ClientSecret"];
options.ResponseType = "code";
options.UsePkce = true;
options.Scope.Clear();
options.Scope.Add("openid");
options.Scope.Add("email");
options.Scope.Add("profile");
options.CallbackPath = "/signin-motaware";
options.SignedOutCallbackPath = "/signout-callback-motaware";
options.SaveTokens = true; // keeps the ID token for sign-out (id_token_hint)
options.MapInboundClaims = false; // keep "sub", "email", "name" as they are
options.TokenValidationParameters.NameClaimType = "name";
});
Read the user id with User.FindFirst("sub").
To sign out of both your site and Motaware, call
SignOut(CookieAuthenticationDefaults.AuthenticationScheme, "Motaware").
Node.js (openid-client v6)
// npm install openid-client
import * as client from "openid-client";
const config = await client.discovery(
new URL("https://auth.motaware.com"),
process.env.MOTAWARE_CLIENT_ID,
process.env.MOTAWARE_CLIENT_SECRET,
);
// Sign-in route: remember verifier + state in the session, then redirect.
const codeVerifier = client.randomPKCECodeVerifier();
const codeChallenge = await client.calculatePKCECodeChallenge(codeVerifier);
const state = client.randomState();
const authUrl = client.buildAuthorizationUrl(config, {
redirect_uri: "https://app.example.com/signin-motaware",
scope: "openid email profile",
code_challenge: codeChallenge,
code_challenge_method: "S256",
state,
});
// res.redirect(authUrl.href)
// Callback route:
const tokens = await client.authorizationCodeGrant(config, currentUrl, {
pkceCodeVerifier: codeVerifier,
expectedState: state,
});
const claims = tokens.claims(); // { sub, email, email_verified, name, ... }
Auth.js / NextAuth
Add Motaware as an OIDC provider. The redirect URL to register is https://your-site/api/auth/callback/motaware.
// auth.ts
import NextAuth from "next-auth";
export const { handlers, auth, signIn, signOut } = NextAuth({
providers: [
{
id: "motaware",
name: "Motaware",
type: "oidc",
issuer: "https://auth.motaware.com/",
clientId: process.env.AUTH_MOTAWARE_ID,
clientSecret: process.env.AUTH_MOTAWARE_SECRET,
checks: ["pkce", "state"],
authorization: { params: { scope: "openid email profile" } },
},
],
});
Other stacks
Any certified OpenID Connect relying-party library works. Give it the discovery URL https://auth.motaware.com/.well-known/openid-configuration,
your client id and secret, the authorization code flow, and PKCE (S256).