Client API. The Codename One framework your app is built on: this runs on the device, not in a backend.

package com.codename1.io.oidc

OpenID Connect (OIDC) client with PKCE.

OidcClient drives the Authorization Code + PKCE flow against any standards-compliant identity provider (Auth0, Okta, Google, Microsoft Entra, Keycloak, …). It launches a system browser via SystemBrowser / OidcBrowserNative, exchanges the authorization code for tokens, and persists them through a pluggable TokenStore.

Companion classes (OidcConfiguration, OidcTokens, PkceChallenge, OidcException) carry configuration, results and errors.

Types

interface OidcBrowserNativeService-provider interface that SystemBrowser uses to dispatch a sign-in flow through the OS’s hardened sign-in surface (ASWebAuthenticationSession on iOS, androidx.browser.customtabs / Credential Manager on Android).
class OidcClientModern OpenID Connect / OAuth 2.0 client.
class OidcConfigurationThe subset of an OpenID Connect provider’s .well-known/openid-configuration document that OidcClient cares about.
class OidcDeviceAuthorizationWhat an authorization server answers when a device starts the device authorization grant (RFC 8628): the code the user types, where they type it, and how the device waits.
class OidcExceptionThrown for failures during an OpenID Connect / OAuth 2.0 flow driven by OidcClient.
class OidcRequestAuthorizerSends an OidcClient’s access token with the application’s requests, and renews it with the refresh token when the service refuses it.
class OidcTokensThe tokens returned by an OpenID Connect token endpoint, with convenience accessors for the OIDC ID token claims.
class PkceChallengeOne PKCE pair (RFC 7636).
class SecureStorageTokenStoreA TokenStore that keeps an OidcClient’s tokens in the platform’s secure storage – the iOS keychain, the Android keystore, and what each desktop and browser port provides – instead of the application’s ordinary Storage.
class SystemBrowserRoutes an authorization-code-flow sign-in through the system browser (ASWebAuthenticationSession on iOS, an Android Custom Tab on Android, the user’s default browser on JavaSE / Web) and resolves with the final redirect URL once the OS hands it back.
interface TokenStorePluggable persistence for an OidcClient’s tokens.