Web apps (server)

Use a Web app (server) client when your server receives the authorization code and keeps the client secret. The secret can go in the request as HTTP Basic (client_secret_basic) or in the form body (client_secret_post); both work. PKCE is required as well, and the libraries below do it for you.

The issuer is https://auth.motaware.com/, ending in a slash. Libraries that compare issuers exactly need that slash.

ASP.NET Core

Register https://your-site/signin-motaware as the redirect URL and https://your-site/signout-callback-motaware as the sign-out return URL.

// dotnet add package Microsoft.AspNetCore.Authentication.OpenIdConnect
builder.Services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = "Motaware";
})
.AddCookie()
.AddOpenIdConnect("Motaware", options =>
{
    options.Authority = "https://auth.motaware.com";
    options.ClientId = builder.Configuration["Motaware:ClientId"];
    options.ClientSecret = builder.Configuration["Motaware:ClientSecret"];
    options.ResponseType = "code";
    options.UsePkce = true;
    options.Scope.Clear();
    options.Scope.Add("openid");
    options.Scope.Add("email");
    options.Scope.Add("profile");
    options.CallbackPath = "/signin-motaware";
    options.SignedOutCallbackPath = "/signout-callback-motaware";
    options.SaveTokens = true;          // keeps the ID token for sign-out (id_token_hint)
    options.MapInboundClaims = false;   // keep "sub", "email", "name" as they are
    options.TokenValidationParameters.NameClaimType = "name";
});

Read the user id with User.FindFirst("sub"). To sign out of both your site and Motaware, call SignOut(CookieAuthenticationDefaults.AuthenticationScheme, "Motaware").

Node.js (openid-client v6)

// npm install openid-client
import * as client from "openid-client";

const config = await client.discovery(
  new URL("https://auth.motaware.com"),
  process.env.MOTAWARE_CLIENT_ID,
  process.env.MOTAWARE_CLIENT_SECRET,
);

// Sign-in route: remember verifier + state in the session, then redirect.
const codeVerifier = client.randomPKCECodeVerifier();
const codeChallenge = await client.calculatePKCECodeChallenge(codeVerifier);
const state = client.randomState();
const authUrl = client.buildAuthorizationUrl(config, {
  redirect_uri: "https://app.example.com/signin-motaware",
  scope: "openid email profile",
  code_challenge: codeChallenge,
  code_challenge_method: "S256",
  state,
});
// res.redirect(authUrl.href)

// Callback route:
const tokens = await client.authorizationCodeGrant(config, currentUrl, {
  pkceCodeVerifier: codeVerifier,
  expectedState: state,
});
const claims = tokens.claims();   // { sub, email, email_verified, name, ... }

Auth.js / NextAuth

Add Motaware as an OIDC provider. The redirect URL to register is https://your-site/api/auth/callback/motaware.

// auth.ts
import NextAuth from "next-auth";

export const { handlers, auth, signIn, signOut } = NextAuth({
  providers: [
    {
      id: "motaware",
      name: "Motaware",
      type: "oidc",
      issuer: "https://auth.motaware.com/",
      clientId: process.env.AUTH_MOTAWARE_ID,
      clientSecret: process.env.AUTH_MOTAWARE_SECRET,
      checks: ["pkce", "state"],
      authorization: { params: { scope: "openid email profile" } },
    },
  ],
});

Other stacks

Any certified OpenID Connect relying-party library works. Give it the discovery URL https://auth.motaware.com/.well-known/openid-configuration, your client id and secret, the authorization code flow, and PKCE (S256).