TRY TRIAD
ONE REQUEST.
THREE FLOWS.
Configure the identity request, then use browser OAuth, first-party device login, or a registered OAuth device client.
CONFIGURE THE CLIENT REQUEST
Requested profile claims default off here. Any selected claim is required for the transaction and shown again at consent.
Choose a provider. Unsupported claims remain unavailable.
- CLIENT ID
- ISSUED ON START
- RESOURCE
- LOADING
- SCOPE
- openid
01 / BROWSER
AUTHORIZATION CODE + PKCE
Triad creates a 64-byte verifier, sends only its S256 challenge, checks state, exchanges the code once, and verifies the returned ES256 token against JWKS.
- AUTH SERVER
- loading
- CLIENT TYPE
- PUBLIC / NONE
- VERIFICATION
- ES256 + JWKS
Loading authorization server metadata.
02 / DEVICE
TWO DEVICE CONTRACTS
Authorize a Triad session on another device, or issue OAuth tokens to a registered device client. Both use the same browser approval step and different token endpoints.
USER CODEOPEN VERIFICATION PAGE ↗
No device request is active.