An OpenID Connect identity provider with strict client policies: authorization
code flow with PKCE only — no implicit flow, no password grant, consent
required for apps, exact redirect-URI matching.
Short-lived access tokens (minutes) with refresh tokens; APIs verify them
locally and refuse tokens that do not name them (aud).
Apps reach services through token exchange (a token per service and
scope set); background work uses client_credentials with mTLS where
available.
Apps are registered and reviewed before they get a client; see
SDK · Publishing.