# Authentication (OAuth 2.0 + PKCE)

INFRA uses standard OAuth 2.0 with PKCE (Proof Key for Code Exchange) for all authorization flows. No proprietary SDK required.

## PKCE flow

1. **Generate PKCE Pair** — Create a cryptographically random code_verifier (43-128 chars). Derive code_challenge = BASE64URL(SHA256(code_verifier)).
2. **Authorization Request** — Redirect user to https://auth.infraidentity.com/oauth2/auth with response_type=code, scopes, state, and code_challenge.
3. **User Consent** — INFRA shows the user a consent screen listing the requested scopes. User approves or denies.
4. **Authorization Code** — INFRA redirects to your redirect_uri with ?code=AUTH_CODE&state=YOUR_STATE.
5. **Token Exchange** — Your backend POSTs to /oauth2/token with the code, code_verifier, client credentials. Receives access_token + refresh_token.
6. **API Calls** — Use the access_token as a Bearer token in the Authorization header for all INFRA API requests.

## Scopes

| Scope | Description | Trust level |
|---|---|---|
| `profile:read` | Name, email, country, profile photo | Standard |
| `kyc:read` | KYC level, status, verification date | Standard |
| `claims:read` | Signed verification claims (age, residency, etc.) | Standard |
| `documents:metadata` | Document type and verification status (no content) | Standard |
| `documents:read` | JWE-encrypted sensitive documents | Trusted |

## Token lifetimes

| Token | Lifetime | Notes |
|---|---|---|
| Access Token | 1 hour | Use for API calls. Refresh when expired. |
| Refresh Token | 30 days | Exchange for new access token. Rotates on use. |

---

Source: https://docs.infraidentity.com/authentication/ · Full docs: https://docs.infraidentity.com/llms-full.txt
