Use this guide to understand all fields and options in the Admin UI.
- Dashboard:
/admin/uishows quick links to Scopes, Users, Clients, and Signing Keys - Login:
/admin/loginrequires the Admin Token created during first-time setup - GitHub Docs: https://github.com/Sbussiso/LOauth2#admin-ui-reference
Create, update, and delete local users used to authenticate on the Authorization Server.
- Path:
/admin/ui/users - Shows ID, Username, Email
- Actions: Edit, Delete (deletes tokens, auth codes, and remembered consents for the user)
- Path:
/admin/ui/users/new - Fields:
- Username (required, unique)
- Email (optional)
- Password (required)
- Path:
/admin/ui/users/<id> - Actions:
- Update Email
- Set New Password (leave blank to keep existing)
- Revoke All Tokens (forces re-login on all clients)
- Path: POST
/admin/ui/users/delete - Effect: Removes the user and cleans up related data (tokens, auth codes, remembered consents)
Create and manage OAuth2/OIDC clients that integrate with this Authorization Server.
-
Open the Admin UI
- Visit
http://127.0.0.1:8000/admin/login - Enter your Admin Token (created during
/setup)
- Visit
-
Go to Clients
- Click
Clientson the dashboard (/admin/ui) - Click
Create Client(orNew)
- Click
-
Fill in basic client info
- Client ID: short, URL-safe name (e.g.,
my-app) - Client Name: shown on consent screens (e.g.,
My App) - Redirect URIs: exact callback URLs (space-separated)
- Examples:
http://localhost:3000/callbackhttp://127.0.0.1:3000/callback
- Must match exactly what your app sends in
redirect_uri
- Examples:
- Client ID: short, URL-safe name (e.g.,
-
Choose client type and auth method
- Public client (SPA/mobile): set Token Endpoint Auth Method to
none - Confidential client (backend): choose
client_secret_postorclient_secret_basic - If confidential, copy the generated client secret after saving
- Public client (SPA/mobile): set Token Endpoint Auth Method to
-
Select grants/response types
- Grant Types: usually
authorization_code refresh_token - Response Types:
code
- Grant Types: usually
-
Set requested scopes
- Scope:
openid profile email offline_access - You can add custom scopes later in
Scopes
- Scope:
-
Configure Client Policy (important)
- Allowed Scopes: must include all scopes your app may request
- Default Scopes: auto-applied if your app omits
scope - Require PKCE: turn ON for public clients (recommended)
- Consent Policy:
once(remember user consent) is a good default - Token Lifetimes: keep defaults for first setup
-
Save and test
- Save the client
- If dev helpers are enabled (
ENABLE_DEV_ENDPOINTS=true), you can generate PKCE at/dev/pkcefor quick testing - Build the
/authorizeURL in your app and try the full flow
- Unique identifier for the client
- Use a simple, stable, URL-safe value
- Examples:
my-app,camera-web,todo-spa
- Human-readable name shown on consent screens
- Example:
My Camera App
- Space- or newline-separated list of exact callback URLs
- Must match the
redirect_uriin authorize/token requests exactly - Examples:
http://localhost:3000/callbackhttps://myapp.example.com/auth/callback
- Space-separated scopes the client will request
- Common:
openid profile email offline_access - Must also be allowed by the client policy (see Allowed Scopes below)
- OAuth2 flows permitted for this client
- Common:
authorization_code refresh_token - Public clients (SPAs/native) should use Authorization Code with PKCE
- Authorization response modes
- Commonly
code
- Public clients: No client secret; must use PKCE (recommended for SPAs/native)
- Confidential clients: Server-side apps that keep a client secret; choose an auth method
- How confidential clients authenticate at
/token - Options:
none(public client)client_secret_post(send secret in POST body)client_secret_basic(send secret in HTTP Basic Auth header)
- If enabled, the user must approve on the consent screen before tokens are issued
- Use together with the Client Policy's Consent Policy (below) to control how often consent is shown
- Space-separated list of scopes this client is permitted to request
- Requests outside this set will be rejected
- Scopes automatically applied when an authorize request does not specify
scope
- Space-separated list of URLs users may be redirected to after logout
- Used by
GET /end_session
- Enforces PKCE S256 for Authorization Code flow
- Strongly recommended for public clients
- Controls consent prompting:
always: ask every timeonce: remember consent per user+client+scopeskip: never show consent screen
- How long access tokens remain valid
- Typical production default:
3600(1 hour)
- How long refresh tokens remain valid
- Tokens are rotated on use
opaque(default): access token is a reference stored server-sidejwt(optional): self-contained access token signed by the server (verify via JWKS)
Define scopes (name, description, claims) in /admin/ui/scopes.
- Scopes appear on consent screens with their descriptions
- Claims listed on a scope can be used to derive ID token or UserInfo content per your implementation
- Unique identifier for the scope
- Examples:
openid,profile,email,files.read
- Human-readable description shown on consent screen
- Example: "Access your basic profile information"
- Space-separated list of claims associated with this scope
- Used to populate ID tokens and UserInfo responses
- Examples:
name email picture,sub preferred_username
Manage and rotate RS256 signing keys in /admin/ui/keys.
- JWKS is published at
/.well-known/jwks.json - Rotating keys preserves old keys to validate historical tokens
- Each key has a unique Key ID (kid) used in JWT headers
- Click "Rotate Key" to generate a new signing key
- Old keys remain available for token verification
- New tokens will be signed with the new key
- Old tokens remain valid until expiration
On first run, visit /setup to initialize the server:
- System generates a random Admin Token
- Token is shown once only (copy it immediately)
- Token is hashed and stored in the database
- Use this token for:
- Admin UI login (
/admin/login) - Admin API requests (
X-Admin-Tokenheader)
- Admin UI login (
Important: Keep your Admin Token secure. If lost, you'll need to reset it via database access.
Disabled by default. Set ENABLE_DEV_ENDPOINTS=true to enable:
GET /dev/seed- Create demo users and clientsGET /dev/pkce- Generate PKCE verifier/challenge
Dev endpoints still require X-Admin-Token when enabled.