Authentication (OAuth 2.0 + PKCE)

INFRA uses standard OAuth 2.0 with PKCE (Proof Key for Code Exchange) for all authorization flows. No proprietary SDK required.

PKCE flow#

  1. Generate PKCE Pair — Create a cryptographically random code_verifier (43-128 chars). Derive code_challenge = BASE64URL(SHA256(code_verifier)).
  2. Authorization Request — Redirect user to https://auth.infraidentity.com/oauth2/auth with response_type=code, scopes, state, and code_challenge.
  3. User Consent — INFRA shows the user a consent screen listing the requested scopes. User approves or denies.
  4. Authorization Code — INFRA redirects to your redirect_uri with ?code=AUTH_CODE&state=YOUR_STATE.
  5. Token Exchange — Your backend POSTs to /oauth2/token with the code, code_verifier, client credentials. Receives access_token + refresh_token.
  6. API Calls — Use the access_token as a Bearer token in the Authorization header for all INFRA API requests.

Scopes#

Scope Description Trust level
profile:read Name, email, country, profile photo Standard
kyc:read KYC level, status, verification date Standard
claims:read Signed verification claims (age, residency, etc.) Standard
documents:metadata Document type and verification status (no content) Standard
documents:read JWE-encrypted sensitive documents Trusted

Token lifetimes#

Token Lifetime Notes
Access Token 1 hour Use for API calls. Refresh when expired.
Refresh Token 30 days Exchange for new access token. Rotates on use.

This page as Markdown: /authentication.md · All docs in one file: /llms-full.txt