Advanced security options
PAR, JAR, and rate limiting for LuxID Partners with elevated security requirements. PAR and JAR are informational only - not currently implemented by LuxID.
PAR, JAR, and rate limiting for LuxID Partners with elevated security requirements. PAR and JAR are informational only - not currently implemented by LuxID.
Ready-made Postman collections, OpenAPI spec, and CI smoke-test scripts for the full LuxID token flow.
Overview of extended LuxID technical capabilities: UserInfo, introspection, revocation, webhooks, delegated authorisation, and cross-border federation.
Read and revoke the subscription that links a LuxID user to one of your applications.
Discover the LuxID-registered applications and instances that belong to your partnership, and the groups attached to each application.
Roadmap: optional enriched claims beyond standard OIDC profile - organisation, age brackets, residency, postal address - each requiring explicit user consent.
A consolidated reference of every parameter LuxID accepts on the authorization endpoint, with its required/optional status, accepted values, and LuxID specifics.
Set or remove a custom claim value on a subscriber, to be surfaced on subsequent authentications.
Curated index of reference repositories, starter templates, and validation utilities for integrating LuxID with the major language ecosystems.
The ten most frequent LuxID integration mistakes, with exact error responses, root causes, and fixes.
How to reach LuxID: the right mailbox for commercial, operational, security and end-user matters, what to include in a ticket, and response targets.
Patterns for one LuxID application acting on behalf of a user at another service: delegated tokens, token exchange, and refresh token scoping.
Copy-paste curl and PowerShell commands to exercise LuxID's OIDC endpoints - discovery, token, refresh, userinfo, introspection - for troubleshooting.
Canonical list of LuxID OIDC, SAML and supporting endpoints for production and UAT, derived from the discovery document - one place to look up every URL.
One-table lookup of LuxID OAuth/OIDC error codes and platform errors: HTTP status, where they surface, likely cause, whether to retry, and the fix.
Search the time-ordered stream of user-related events tied to your partnership's applications, with pagination.
Overview of LuxID identity events: the common event envelope, pull vs push delivery, the indicative event catalogue, and SIEM integration.
Frequently asked questions about integrating LuxID: onboarding, protocol support, tokens, claims, MFA, LuxID Verified, LuxID Pro, compliance, and operations.
LuxID OIDC endpoints, scopes, claims, and field mapping reference for any tool that asks for OpenID Connect provider details.
LuxID SAML 2.0 IdP metadata, entity ID, ACS URL expectations, attribute mapping, and field reference for any SAML-capable tool.
Authentication, base URLs, request and response conventions, and the standard error model for the LuxID Partner API.
Alphabetical glossary of LuxID developer terms: entities, tokens, claims, protocols, and authentication concepts, each linked to its canonical page.
List partner-managed groups, list members, list a user's group memberships, and add or remove members in bulk.
How LuxID signs ID Tokens, how to validate signatures using the JWKS endpoint, key rotation behaviour, and client credential security.
Querying authentication logs, Subscription events, and configuration audit records in the LuxID Console, including filtering, export, and retention.
Landing page for the LuxID developer documentation: positioning, supported standards, top-level navigation, and persona entry points.
The four LuxID diagnostic identifiers - Error ID, Transaction ID, Support ID, and Global Transaction ID - where each appears and which one to ask a user for.
Server-to-server REST API for LuxID Partners to manage applications, subscriptions, groups, custom claims, and user events programmatically.
LuxID Verified confirms a user's name and date of birth via LuxTrust: verification process, token claims, use cases, and relay-only LoA provenance.
LuxID MFA methods (OTP, TOTP, passkeys, LuxTrust), token claims amr and acr, minimum assurance configuration, step-up flows, and recovery paths.
Reference catalogue of OAuth 2.0 and OIDC error codes at LuxID with the most common cause and fix for each.
Full OIDC protocol reference for LuxID: discovery, all request parameters, token validation, UserInfo, refresh, silent re-auth, logout, and response modes.
How LuxID rate limits the authorize, token and UserInfo endpoints, and how to handle HTTP 429 with Retry-After and exponential backoff.
Entry point for security and compliance officers assessing LuxID: responsibility split, key controls, retention, and where each claim is documented.
LuxID evaluates each sign-in against contextual security signals and surfaces a qualitative risk indicator as an ID Token claim for Partner use.
LuxID RFC 7662 token introspection reference: request format, response fields, caching, and why local JWT validation is preferred today.
Revoke refresh tokens or access tokens programmatically using the RFC 7009 revocation endpoint, and understand the relationship with user-initiated revocation.
Diagnosing ID Token and JWT validation failures at LuxID: signature, issuer, audience, expiry, nonce, at_hash, and algorithm confusion.
ID Token, Access Token, and Refresh Token explained in depth: lifetimes, signing, validation rules, and the full LuxID claim catalogue including extensions.
Call the LuxID UserInfo endpoint with a Bearer access token to fetch current profile claims: request formats, response claims, caching, and errors.
Subscribe to LuxID identity events via push (webhooks) or pull (Event Hub): subscription management, payload signing, delivery semantics, and replay protection.