Documentation
Integrate in an afternoon.
YourID is a standard OpenID Connect provider. Authorization code flow with PKCE, RS256 tokens, published keys. If your stack has an OIDC library, it has YourID support.
Drop-in button
No backend, no OIDC library. Paste one script, get a “Login with YourID” button that runs the whole PKCE flow in the browser and hands you the user’s approved claims. Register a public client to get a client_id.
index.html
<script src="https://yourid-web.vercel.app/yourid.js"></script>
<div id="yourid-button"></div>
<script>
YourID.configure({ clientId: "yid_your_public_client", scope: "openid email" });
YourID.mount("#yourid-button");
// On the page users return to:
YourID.handleRedirect().then(function (user) {
if (user) console.log("Signed in:", user); // { sub, email, email_verified }
});
</script>That’s the entire integration. Works on static sites and single-page apps — no backend needed.
Endpoints
| GET | /.well-known/openid-configuration | Discovery document — start here |
| GET | /authorize | Authorization endpoint (code + PKCE only) |
| POST | /api/oidc/token | Token endpoint (authorization_code, refresh_token) |
| GET | /api/oidc/userinfo | UserInfo endpoint (Bearer access token) |
| GET | /api/oidc/jwks | Public signing keys (RS256) |
| POST | /api/oidc/revoke | Token revocation |
Scopes & claims
Request the minimum you need. Users see every claim on the consent screen and can revoke access at any time — revoking cuts off your access and refresh tokens immediately.
openidrequiredStable subject identifier (sub). No personal data.emailworks todayemail + email_verified.profile:personal / profile:businessworks todayFields the user filled in themselves, shared as a namespaced object — only the fields they approve on the consent screen.ageneeds ID verificationage_over_18: true/false — derived, never the birthdate. Empty until identity-document verification is live (coming soon).profileneeds ID verificationgiven_name, family_name, name — verified, plus tier and verification_method. Empty until verification is live.birthdateneeds ID verificationbirthdate (verified), as its own scope so a name never brings the birthdate along.The whole integration
auth.js — Node, with openid-client
import * as client from "openid-client";
const config = await client.discovery(
new URL("https://yourid-web.vercel.app"),
process.env.YOURID_CLIENT_ID,
process.env.YOURID_CLIENT_SECRET
);
// 1. Send the user to YourID
const codeVerifier = client.randomPKCECodeVerifier();
const url = client.buildAuthorizationUrl(config, {
redirect_uri: "https://your-site.example/auth/callback",
scope: "openid email",
code_challenge: await client.calculatePKCECodeChallenge(codeVerifier),
code_challenge_method: "S256",
state: client.randomState(),
});
// 2. Handle the callback
const tokens = await client.authorizationCodeGrant(config, callbackUrl, {
pkceCodeVerifier: codeVerifier,
expectedState: state,
});
// 3. Read the claims — that's it
const { sub, email, email_verified } = tokens.claims();Try the golden path
- 1.Get a YourID: YourID is in private beta, so request access and sign in to the user app once you're invited.
- 2.Open the demo bank (a fictional example) and choose “Login with YourID”.
- 3.Approve the consent screen and see exactly which claims the bank receives — then revoke it from your dashboard and watch its access stop. Age checks (
age_over_18) follow once ID verification is live. - 4.Register your own client on the developer dashboard and point your OIDC library at the discovery document.