Endpoints overview
This page is the authoritative reference for the public Klubero SSO endpoints used in third-party integrations. The endpoints are split into standard OpenID Connect endpoints and the service (M2M) REST API.
Core OIDC endpoints
These are the standard OpenID Connect endpoints:
| Endpoint | URL | Description |
|---|---|---|
| Discovery | /.well-known/openid-configuration | OpenID configuration metadata |
| JWKS | /.well-known/jwks | Public keys for token verification |
| Authorization | /connect/authorize | Start the OAuth flow |
| Token | /connect/token | Exchange the code for tokens |
| UserInfo | /connect/userinfo | Retrieve the user's claims |
| Logout | /connect/logout | End the user's session |
| Introspection | /connect/introspect | Validate a token |
| Revocation | /connect/revoke | Revoke a token |
Discovery endpoint
The discovery endpoint provides all the configuration needed to integrate with Klubero SSO:
curl https://your-sso-domain.com/.well-known/openid-configuration
Response:
{
"issuer": "https://your-sso-domain.com/",
"authorization_endpoint": "https://your-sso-domain.com/connect/authorize",
"token_endpoint": "https://your-sso-domain.com/connect/token",
"userinfo_endpoint": "https://your-sso-domain.com/connect/userinfo",
"end_session_endpoint": "https://your-sso-domain.com/connect/logout",
"introspection_endpoint": "https://your-sso-domain.com/connect/introspect",
"revocation_endpoint": "https://your-sso-domain.com/connect/revoke",
"jwks_uri": "https://your-sso-domain.com/.well-known/jwks",
"scopes_supported": ["openid", "profile", "email", "phone", "address", "offline_access", "api"],
"response_types_supported": ["code"],
"grant_types_supported": ["authorization_code", "refresh_token", "client_credentials"],
"code_challenge_methods_supported": ["S256", "plain"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post"]
}
The issuer value is derived dynamically from the host the discovery document is loaded from. Always read the actual values from the live discovery endpoint, not from this example.
Service REST API (M2M)
In addition to OIDC, Klubero SSO provides a service REST API for management. These endpoints are intended for service-to-service (machine-to-machine) communication.
| Category | Base Path | Description |
|---|---|---|
| Users | /api/users/* | User management |
| Sessions | /api/sessions/* | Session management |
| Magic Link | /api/magiclink/* | Passwordless authentication |
| Two-Factor (management) | /api/twofactor/{guid}/* | User 2FA management |
The /api/* endpoints (except those explicitly anonymous) require an M2M access token obtained via the Client Credentials flow with the api scope. User tokens obtained via the Authorization Code Flow do not have access to these management endpoints. For details, see Scopes and Claims.