Skip to main content

Protocols & Standards

ThunderID is built on open identity and access standards. Each section on this page links to its own guides, with per-spec pages covering what it is, how it works, and how to enable it on your application.

OAuth & OIDC

The core stack for delegated authorization and federated authentication. Covers OAuth 2.1 grant types, OpenID Connect Core 1.0, client authentication, token operations, and dynamic client registration, plus security extensions such as PKCE, PAR, DPoP, and Resource Indicators.

Browse the OAuth & OIDC catalogue →

Verifiable Credentials

Standards for requesting and verifying digital credentials held in a wallet. Covers OpenID for Verifiable Presentations (OpenID4VP): a protocol that lets a relying party request wallet-held credentials and verify them without requiring a password.

Browse the Verifiable Credentials catalogue →

AuthZEN

Standard Authorization API for asking a policy decision point whether a subject can perform an action on a resource. Covers the AuthZEN roles and ThunderID as an AuthZEN policy decision point, including access evaluation, batch evaluation, action search, and metadata discovery.

Browse the AuthZEN guide →

Explore with AI

ThunderID LogoThunderID Logo

Product

DocsAPIsSDKs
© Copyright Linux Foundation Europe.For web site terms of use, trademark policy and other project policies please see https://linuxfoundation.eu/en/policies.