Client API. The Codename One framework your app is built on: this runs on the device, not in a backend.
package com.codename1.io.oidc
OpenID Connect (OIDC) client with PKCE.
OidcClient drives the Authorization Code + PKCE flow against any
standards-compliant identity provider (Auth0, Okta, Google, Microsoft
Entra, Keycloak, …). It launches a system browser via
SystemBrowser / OidcBrowserNative, exchanges the authorization code
for tokens, and persists them through a pluggable TokenStore.
Companion classes (OidcConfiguration, OidcTokens, PkceChallenge,
OidcException) carry configuration, results and errors.
Types
interface OidcBrowserNative | Service-provider interface that SystemBrowser uses to dispatch a sign-in flow through the OS’s hardened sign-in surface (ASWebAuthenticationSession on iOS, androidx.browser.customtabs / Credential Manager on Android). |
class OidcClient | Modern OpenID Connect / OAuth 2.0 client. |
class OidcConfiguration | The subset of an OpenID Connect provider’s .well-known/openid-configuration document that OidcClient cares about. |
class OidcDeviceAuthorization | What an authorization server answers when a device starts the device authorization grant (RFC 8628): the code the user types, where they type it, and how the device waits. |
class OidcException | Thrown for failures during an OpenID Connect / OAuth 2.0 flow driven by OidcClient. |
class OidcRequestAuthorizer | Sends an OidcClient’s access token with the application’s requests, and renews it with the refresh token when the service refuses it. |
class OidcTokens | The tokens returned by an OpenID Connect token endpoint, with convenience accessors for the OIDC ID token claims. |
class PkceChallenge | One PKCE pair (RFC 7636). |
class SecureStorageTokenStore | A TokenStore that keeps an OidcClient’s tokens in the platform’s secure storage – the iOS keychain, the Android keystore, and what each desktop and browser port provides – instead of the application’s ordinary Storage. |
class SystemBrowser | Routes an authorization-code-flow sign-in through the system browser (ASWebAuthenticationSession on iOS, an Android Custom Tab on Android, the user’s default browser on JavaSE / Web) and resolves with the final redirect URL once the OS hands it back. |
interface TokenStore | Pluggable persistence for an OidcClient’s tokens. |