Authentication (OAuth 2.0 + PKCE)
INFRA uses standard OAuth 2.0 with PKCE (Proof Key for Code Exchange) for all authorization flows. No proprietary SDK required.
PKCE flow#
- Generate PKCE Pair — Create a cryptographically random code_verifier (43-128 chars). Derive code_challenge = BASE64URL(SHA256(code_verifier)).
- Authorization Request — Redirect user to https://auth.infraidentity.com/oauth2/auth with response_type=code, scopes, state, and code_challenge.
- User Consent — INFRA shows the user a consent screen listing the requested scopes. User approves or denies.
- Authorization Code — INFRA redirects to your redirect_uri with ?code=AUTH_CODE&state=YOUR_STATE.
- Token Exchange — Your backend POSTs to /oauth2/token with the code, code_verifier, client credentials. Receives access_token + refresh_token.
- API Calls — Use the access_token as a Bearer token in the Authorization header for all INFRA API requests.
Scopes#
| Scope |
Description |
Trust level |
profile:read |
Name, email, country, profile photo |
Standard |
kyc:read |
KYC level, status, verification date |
Standard |
claims:read |
Signed verification claims (age, residency, etc.) |
Standard |
documents:metadata |
Document type and verification status (no content) |
Standard |
documents:read |
JWE-encrypted sensitive documents |
Trusted |
Token lifetimes#
| Token |
Lifetime |
Notes |
| Access Token |
1 hour |
Use for API calls. Refresh when expired. |
| Refresh Token |
30 days |
Exchange for new access token. Rotates on use. |
This page as Markdown: /authentication.md · All docs in one file: /llms-full.txt