Protocols & Standards
ThunderID is built on open identity and access standards. Each section on this page links to its own guides, with per-spec pages covering what it is, how it works, and how to enable it on your application.
OAuth & OIDC
The core stack for delegated authorization and federated authentication. Covers OAuth 2.1 grant types, OpenID Connect Core 1.0, client authentication, token operations, and dynamic client registration, plus security extensions such as PKCE, PAR, DPoP, and Resource Indicators.
Verifiable Credentials
Standards for requesting and verifying digital credentials held in a wallet. Covers OpenID for Verifiable Presentations (OpenID4VP): a protocol that lets a relying party request wallet-held credentials and verify them without requiring a password.