DocumentaciónIniciar sesión con Learnya
Operar
Iniciar sesión con Learnya
Permite que las personas inicien sesión en tu aplicación con su cuenta de Learnya. OAuth 2.1 y OpenID Connect, en auth.learnya.ai.
En esta página
El documento de descubrimiento
Todo lo que necesita una biblioteca OpenID Connect está publicado en una URL. La mayoría se configuran solo con ella.
curl https://auth.learnya.ai/.well-known/openid-configuration{
"issuer": "https://auth.learnya.ai",
"authorization_endpoint": "https://auth.learnya.ai/authorize",
"token_endpoint": "https://auth.learnya.ai/token",
"jwks_uri": "https://auth.learnya.ai/.well-known/jwks.json",
"grant_types_supported": [
"authorization_code",
"refresh_token",
"client_credentials",
"urn:ietf:params:oauth:grant-type:token-exchange"
],
"code_challenge_methods_supported": ["S256"]
}Qué flujo elegir
| Tu caso | Flujo OAuth |
|---|---|
| Una persona inicia sesión en tu aplicación | authorization_code |
| Tu servidor actúa en su propio nombre | client_credentials |
| Mantener una sesión abierta | refresh_token |
| Un servicio actúa en nombre de otro | token-exchange |
Código de autorización con PKCE
PKCE es obligatorio para todas las aplicaciones, con el método S256. La URL de redirección debe coincidir exactamente con la registrada.
Enviar a la persona a iniciar sesión
GET https://auth.learnya.ai/authorize ?response_type=code &client_id=lyc_your_client &redirect_uri=https://app.example.ch/callback &scope=openid profile email offline_access &state=a value you check on return &code_challenge=BASE64URL(SHA256(verifier)) &code_challenge_method=S256Canjear el código por tokens
curl https://auth.learnya.ai/token \ -u "lyc_your_client:$CLIENT_SECRET" \ -d grant_type=authorization_code \ -d code=the_code_from_the_callback \ -d redirect_uri=https://app.example.ch/callback \ -d code_verifier=the_verifier_you_generatedRespuesta{ "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6ImF0K2p3dCJ9…", "token_type": "Bearer", "expires_in": 900, "refresh_token": "…", "id_token": "eyJhbGciOiJSUzI1NiJ9…", "scope": "openid profile email offline_access" }
Verificar un token
Los tokens de acceso son JWT firmados con RS256. Verifícalos con las claves públicas publicadas, sin secreto compartido. Cuentan cinco comprobaciones: el algoritmo fijado en RS256, el tipo at+jwt, el emisor, tu audiencia y la caducidad.
import jwt from "jsonwebtoken"
const ISSUER = "https://auth.learnya.ai"
const AUDIENCE = "https://api.example.ch"
// keyFor maps a kid to a public key from the JWKS.
export function verifyAccessToken(token, keyFor) {
const decoded = jwt.decode(token, { complete: true })
if (!decoded?.header.kid) throw new Error("no kid in header")
if (decoded.header.typ !== "at+jwt")
throw new Error("not an access token")
return jwt.verify(token, keyFor(decoded.header.kid), {
algorithms: ["RS256"],
issuer: ISSUER,
audience: AUDIENCE,
})
}import type { KeyObject } from "node:crypto"
import jwt, { type JwtPayload } from "jsonwebtoken"
const ISSUER = "https://auth.learnya.ai"
const AUDIENCE = "https://api.example.ch"
// keyFor maps a kid to a public key from the JWKS.
export function verifyAccessToken(
token: string,
keyFor: (kid: string) => KeyObject,
): JwtPayload {
const decoded = jwt.decode(token, { complete: true })
if (!decoded?.header.kid) throw new Error("no kid in header")
if (decoded.header.typ !== "at+jwt")
throw new Error("not an access token")
const payload = jwt.verify(
token,
keyFor(decoded.header.kid),
{
algorithms: ["RS256"],
issuer: ISSUER,
audience: AUDIENCE,
},
)
if (typeof payload === "string")
throw new Error("not a JSON payload")
return payload
}También disponible
| Función | Para |
|---|---|
| Solicitudes de autorización enviadas (PAR) | Enviar la petición al servidor en lugar de ponerla en la URL |
| DPoP | Vincular un token a una clave que tiene tu aplicación |
| Revocación e introspección | Anular un token, o preguntar si sigue siendo válido |
| Cierre de sesión | Cerrar la sesión de Learnya desde tu aplicación |
Registrar tu aplicación
Learnya registra cada aplicación con sus URL de redirección exactas. Escríbenos con el nombre de tu aplicación, sus URL de redirección y los datos que necesitas sobre la persona.