TRY TRIAD

ONE REQUEST.
THREE FLOWS.

Configure the identity request, then use browser OAuth, first-party device login, or a registered OAuth device client.

CONFIGURE THE CLIENT REQUEST

Requested profile claims default off here. Any selected claim is required for the transaction and shown again at consent.

OPTIONAL CLAIM REQUEST

Choose a provider. Unsupported claims remain unavailable.

CLIENT ID
ISSUED ON START
RESOURCE
LOADING
SCOPE
openid
01 / BROWSER

AUTHORIZATION CODE + PKCE

Triad creates a 64-byte verifier, sends only its S256 challenge, checks state, exchanges the code once, and verifies the returned ES256 token against JWKS.

AUTH SERVER
loading
CLIENT TYPE
PUBLIC / NONE
VERIFICATION
ES256 + JWKS

Loading authorization server metadata.

02 / DEVICE

TWO DEVICE CONTRACTS

Authorize a Triad session on another device, or issue OAuth tokens to a registered device client. Both use the same browser approval step and different token endpoints.

No device request is active.