Apps
A standard OpenID Connect issuer.
Each brand is an OpenID Connect issuer at https://<your-slug>.auth.synq.build. Any OpenID Connect library can use it, and nothing about it is ours alone.
The code flow, with PKCE
The authorization code flow only, with PKCE on every request and redirect URIs matched exactly.
Refresh tokens that rotate
Every refresh token works once. One presented again revokes its whole grant, so a stolen token gives itself away.
Keys that rotate
Signing keys are encrypted at rest. A new key is published a day before it signs and stays published a day after, so apps that cache keys never break.
Signing out everywhere
RP-initiated sign-out, and back-channel logout tokens to your apps when Synq ends a session itself.
Built on oidc-provider
The protocol core is oidc-provider, a widely used open-source OpenID Connect library, so standard OpenID Connect clients work with Synq as they are.
Read next
Want it before it is finished?
Tell us what you are building and which sign-in your users need.