Skip to main content

109 docs tagged with "for-developers"

View all tags

Accessibility and localisation

WCAG 2.2 AA compliance, ARIA patterns, keyboard navigation, lang, the LuxID language fall-back chain, and inclusive wording guidance for LuxID integrations.

Add login to your Application

15-minute quickstart: implement Authorization Code Flow with PKCE against LuxID, with cURL examples, sequence diagram, and ID token validation.

Advanced security options

PAR, JAR, and rate limiting for LuxID Partners with elevated security requirements. PAR and JAR are informational only - not currently implemented by LuxID.

APIs and advanced

Overview of extended LuxID technical capabilities: UserInfo, introspection, revocation, webhooks, delegated authorisation, and cross-border federation.

Applications

Discover the LuxID-registered applications and instances that belong to your partnership, and the groups attached to each application.

Attribute enrichment

Roadmap: optional enriched claims beyond standard OIDC profile - organisation, age brackets, residency, postal address - each requiring explicit user consent.

Attribute preview tool

Inspect which claims will be released to your application for a given test user and application configuration, before going live.

Authenticate

Overview of LuxID authentication protocols - OIDC, OAuth 2.0, and SAML 2.0 - with guidance on choosing the right approach for your integration.

Authentication levels

LuxID's auth_level authentication-strength scale, its informal eIDAS LoA alignment, and how to request a minimum level with acr_values.

Authorization request parameters

A consolidated reference of every parameter LuxID accepts on the authorization endpoint, with its required/optional status, accepted values, and LuxID specifics.

Branding configuration

Configuring per-Application logos, display names, and localised descriptions shown on the LuxID consent screen, and previewing them before go-live.

Breached password detection

LuxID checks passwords against breach intelligence at registration and reset, blocking compromised credentials before they reach your users' accounts.

Calling LuxID reliably

Operational guidance for integrating with LuxID: timeouts, retries and backoff, idempotency, JWKS caching, and how to behave during a LuxID outage.

Change management and roadmap

How LuxID communicates platform changes to Partners: change categories, notification windows, deprecation policy, communication channels and roadmap visibility.

Claims

Set or remove a custom claim value on a subscriber, to be surfaced on subsequent authentications.

Client credentials

Viewing and rotating Client Secrets, and SAML signing certificate lifecycle in the LuxID Console.

Code samples and reference repos

Curated index of reference repositories, starter templates, and validation utilities for integrating LuxID with the major language ecosystems.

Coming from Auth0, Okta or Keycloak

Concept-mapping guide for developers used to multi-tenant IdPs: what maps to what on LuxID, what stays standard OIDC, and what you cannot customize.

Common errors

The ten most frequent LuxID integration mistakes, with exact error responses, root causes, and fixes.

Concepts and fundamentals

Shared vocabulary and mental model for architects, senior developers, and security engineers integrating with LuxID.

Configure LuxID

End-to-end guide: become a LuxID Partner, register an Application, obtain credentials, and complete a first test login using Authorization Code + PKCE.

Consent screen design

How the LuxID consent screen works, what your application name and logo contribute, per-claim labelling, and tone-of-language guidance.

Consent simulator

Preview the exact consent screen your application will show to users, across all supported languages, before going live.

Contact and support channels

How to reach LuxID: the right mailbox for commercial, operational, security and end-user matters, what to include in a ticket, and response targets.

Delegated authorisation

Patterns for one LuxID application acting on behalf of a user at another service: delegated tokens, token exchange, and refresh token scoping.

Diagnose a failing request

A decision tree for diagnosing LuxID integration errors, which on-screen identifier to capture, and what to include when you raise a support ticket.

Endpoint cheat sheet

Copy-paste curl and PowerShell commands to exercise LuxID's OIDC endpoints - discovery, token, refresh, userinfo, introspection - for troubleshooting.

Endpoints reference

Canonical list of LuxID OIDC, SAML and supporting endpoints for production and UAT, derived from the discovery document - one place to look up every URL.

Environments

How LuxID's Production and UAT environments differ, how to promote an Application between them, and data residency details.

Error and edge-case UX

Recommended microcopy for LuxID error states - access denied, network failure, expired session, account blocked - in English, French, German and Luxembourgish.

Error reference

One-table lookup of LuxID OAuth/OIDC error codes and platform errors: HTTP status, where they surface, likely cause, whether to retry, and the fix.

Event Hub

Search the time-ordered stream of user-related events tied to your partnership's applications, with pagination.

Events and Event Hub

Overview of LuxID identity events: the common event envelope, pull vs push delivery, the indicative event catalogue, and SIEM integration.

Features

Overview of LuxID value-add features beyond basic OIDC login: MFA, passkeys, identity verification, SSO, security signals, and more.

Frequently asked questions

Frequently asked questions about integrating LuxID: onboarding, protocol support, tokens, claims, MFA, LuxID Verified, LuxID Pro, compliance, and operations.

FusionAuth

Add LuxID as an OpenID Connect Identity Provider in FusionAuth, including the reconcile lambda for claim mapping, testing, and production checklist.

GDPR and data protection

GDPR guidance for LuxID Partners: controller and processor roles, lawful basis, data minimisation, user rights, breach notification and cross-border transfers.

Generic OIDC broker

Configure any OIDC-capable identity broker against LuxID: discovery URL, PKCE (S256), RS256 ID tokens, exact-match redirect URIs, and JWKS rotation.

Generic OIDC setup

LuxID OIDC endpoints, scopes, claims, and field mapping reference for any tool that asks for OpenID Connect provider details.

Get started

Orientation for developers and IT leads integrating with LuxID: what this section covers, two integration ramps, and where to begin.

Glossary

Alphabetical glossary of LuxID developer terms: entities, tokens, claims, protocols, and authentication concepts, each linked to its canonical page.

Governance, trust and compliance

Overview of LuxID's legal structure, trust framework, compliance obligations and Partner governance for enterprise and regulated integrations.

Groups

List partner-managed groups, list members, list a user's group memberships, and add or remove members in bulk.

How to read this documentation

Mental model for navigating the LuxID developer documentation: five layers, persona-based reading paths, and one-sentence summary per top-level section.

Identity broker integrations

Configure LuxID as an upstream OIDC provider behind your own broker: Keycloak, FusionAuth, Matrix (Synapse, MAS), SAP Customer Data Cloud, or generic OIDC.

Identity fundamentals

Authentication, authorisation, federation, sessions vs tokens, open standards, and JWT structure explained for LuxID integrators.

Integration security checklist

A self-test checklist for LuxID Partners: what to verify in your own OIDC/OAuth 2.0 integration, and what LuxID enforces for you.

Key management

How LuxID signs ID Tokens, how to validate signatures using the JWKS endpoint, key rotation behaviour, and client credential security.

Keycloak

Add LuxID as an external OpenID Connect identity provider in Keycloak (Identity Brokering): field mapping, claim mappers, testing, production checklist.

Learn the basics

Core identity concepts and the LuxID domain model you need before writing any integration code.

Login button guidelines

The official LuxID sign-in button: the four modes, sizes and spacing, allowed text in each language, contrast rules, and CSS patterns.

Logs and audit trails

Querying authentication logs, Subscription events, and configuration audit records in the LuxID Console, including filtering, export, and retention.

LuxID as OpenRoaming IdP

LuxID acts as an OpenRoaming Wi-Fi identity provider, letting users roam onto participating networks in Luxembourg without re-authentication.

LuxID Console

Overview of the LuxID Console - the operational portal for Partner administrators to manage Applications, credentials, logs, and branding.

LuxID developer documentation

Landing page for the LuxID developer documentation: positioning, supported standards, top-level navigation, and persona entry points.

LuxID identifiers reference

The four LuxID diagnostic identifiers - Error ID, Transaction ID, Support ID, and Global Transaction ID - where each appears and which one to ask a user for.

LuxID onboarding

What LuxID is, its governance structure, ecosystem role in Luxembourg, and the use cases it is designed for.

LuxID Partner API

Server-to-server REST API for LuxID Partners to manage applications, subscriptions, groups, custom claims, and user events programmatically.

Matrix homeserver (Synapse and MAS)

Configure LuxID as an OIDC provider for a Matrix homeserver: legacy Synapse built-in OIDC and the next-gen Matrix Authentication Service (MAS).

Multi-factor authentication

LuxID MFA methods (OTP, TOTP, passkeys, LuxTrust), token claims amr and acr, minimum assurance configuration, step-up flows, and recovery paths.

Multi-factor UX

Step-up authentication UX, per-method flows for OTP, TOTP, passkeys, and LuxTrust, recovery paths, lockout prevention, and re-authentication patterns.

OAuth 2.0 for APIs

Protecting backend APIs with OAuth 2.0 bearer tokens, scopes, audiences, and machine-to-machine patterns at LuxID.

OAuth and OIDC error codes

Reference catalogue of OAuth 2.0 and OIDC error codes at LuxID with the most common cause and fix for each.

OpenID Connect

Full OIDC protocol reference for LuxID: discovery, all request parameters, token validation, UserInfo, refresh, silent re-auth, logout, and response modes.

Passkeys and WebAuthn: what runs where

All WebAuthn passkey ceremonies run on LuxID Universal Login - Partners never call WebAuthn APIs. What you observe in tokens and what it means for native apps.

Passwordless and passkey UX

Passkey education, device binding, browser compatibility, fallback flows, and cross-device sign-in UX for LuxID integrations.

Passwordless and passkeys

WebAuthn/FIDO2 passkeys on LuxID: device binding, platform and roaming authenticators, token claims, fallback behaviour, and phishing resistance.

Plan and design

Architectural decisions to make before writing production code: protocol, required auth_level, MFA, Sphere, session strategy, logout, and branding.

Platform and framework guides

Minimal configuration to wire LuxID into Spring, ASP.NET, Node.js, Next.js, React SPA, Angular, React Native, iOS, Android, PHP, and Python.

Privacy and consent

Data minimisation, explicit consent, revocability, Sphere-based pseudonymisation, and GDPR alignment in LuxID.

Protect your Application

Security checklist for LuxID integrations: HTTPS, PKCE, state/nonce, ID Token validation, token storage, open redirects, and anti-patterns to avoid.

Rate limits and quotas

How LuxID rate limits the authorize, token and UserInfo endpoints, and how to handle HTTP 429 with Retry-After and exponential backoff.

Redirect and domain issues

Diagnosing redirect_uri mismatches, HTTPS misconfigurations, mobile deep-link issues, and SAML ACS URL problems at LuxID.

Redirect URIs and domains

Rules, configuration steps, and troubleshooting guidance for redirect URIs and domain ownership in LuxID Applications.

Register an Application

What to submit to register a new client Application with LuxID: required fields, claim declarations, access rules, and authentication level configuration.

Roles in the ecosystem

The LuxID domain model: User, Organisation, Partner, Application, Sphere, Subscription, Group, Claim, Consent, and Federation explained with worked examples.

SAML 2.0

Integrating LuxID as a SAML 2.0 Identity Provider: metadata, AuthnRequest, Assertion validation, attribute mapping, and logout behaviour.

Sandbox environment

How to use the LuxID UAT environment for development and QA: what differs from production, rate limits, test data lifecycle, and promoting to production.

SAP Customer Data Cloud

Configure LuxID as an OpenID Connect identity provider in SAP Customer Data Cloud (formerly Gigya): field mapping, JIT account behaviour, and common pitfalls.

Secure

Security guidance for LuxID integrations: application protection, session lifecycle, key management, and advanced options such as PAR and JAR.

Security signals and risk scoring

LuxID evaluates each sign-in against contextual security signals and surfaces a qualitative risk indicator as an ID Token claim for Partner use.

Service provider onboarding

End-to-end journey for becoming a LuxID Partner: from first contact through KYB, agreement, UAT integration, go-live review to production credentials.

Session management

How to persist refresh tokens, silently renew sessions, and avoid re-prompting users for credentials and OTP on every app restart.

Single sign-on and LuxID Pro

Consumer SSO across LuxID-enabled apps and LuxID Pro enterprise federation: Sphere boundaries, domain routing, corporate IdP integration, token claims.

SLA and support

LuxID service-level commitments for Partners: availability targets, maintenance windows, incident severities, support channels, and DORA considerations.

Test users and simulation

Creating and configuring test user accounts in UAT, simulating authentication scenarios, and resetting test user state in the LuxID Console.

Testing and tooling

Overview of the LuxID developer tools and UAT environment for faster integration development and QA.

Token debugger

How to inspect and validate LuxID ID Tokens and Access Tokens using the Token Debugger tool and offline alternatives.

Token introspection

LuxID RFC 7662 token introspection reference: request format, response fields, caching, and why local JWT validation is preferred today.

Token revocation

Revoke refresh tokens or access tokens programmatically using the RFC 7009 revocation endpoint, and understand the relationship with user-initiated revocation.

Token validation issues

Diagnosing ID Token and JWT validation failures at LuxID: signature, issuer, audience, expiry, nonce, at_hash, and algorithm confusion.

Tokens and claims

ID Token, Access Token, and Refresh Token explained in depth: lifetimes, signing, validation rules, and the full LuxID claim catalogue including extensions.

Troubleshooting and support

Start here when your LuxID integration breaks. Decision flow, child page index, and escalation path for developers and IT admins.

Trust framework

LuxID's legal entity structure, responsibility allocation between operator, Partners and users, assurance model, audit obligations and security baseline.

Universal Login

LuxID's hosted login page: redirect-based authentication, branding boundaries, session reuse, and why Partners should never build their own login form.

Universal Login UX

Why redirect-based login is safer, what the LuxID hosted page guarantees, branding boundaries, mobile/desktop differences, and session reuse behaviour.

User journey patterns

End-to-end sequence diagrams for first-time sign-in, returning sign-in, MFA challenge, LuxID Verified, LuxID Pro federation, account linking, and logout.

UserInfo endpoint

Call the LuxID UserInfo endpoint with a Bearer access token to fetch current profile claims: request formats, response claims, caching, and errors.

UX and branding

Design and branding guidelines for integrating LuxID sign-in consistently, accessibly, and in a way users across Luxembourg recognise and trust.

Webhooks and events API

Subscribe to LuxID identity events via push (webhooks) or pull (Event Hub): subscription management, payload signing, delivery semantics, and replay protection.