Expand description
The OAuth client-identity documents: client-metadata.json and the
client_id derived from it.
Two client shapes, chosen by ClientConfig::dev:
-
dev / localhost — atproto’s special localhost development client. The
client_idishttp://localhostwithredirect_uriandscopeencoded as query parameters; no JWKS and no published metadata document are required, so a dev stack boots with zero PKI. -
production — a confidential client with a real, edge-reachable metadata document, a published JWKS, and
private_key_jwtauthentication using the key fromsuper::keys.
The external URLs deliberately match the sidecar’s. client_id is not
merely a config value — it IS the client’s identity, and a PDS stores it
against every existing grant. The sidecar is mounted at /oauth by the edge
proxy, so its metadata document is externally …/oauth/client-metadata.json
and its callback …/oauth/callback. Serving those same paths from the Rust
app keeps client_id stable across the cutover, so existing authorizations
survive and a rollback does not strand them either.
Structs§
- Client
Config - Everything the client documents are derived from.
Functions§
- client_
id - The client’s identity.
- client_
metadata - The
client-metadata.jsondocument. - jwks_
uri - Where the published JWKS lives. Production only — the localhost dev client does not use one.
- redirect_
uri - Where the browser is sent back to after the PDS authorizes (or denies).