OIDC CLI
A command line tool for working with OIDC
Installation
-
Download a released binary: https://github.com/ctron/oidc-cli/releases
-
From source with
cargo: -
A binary with
cargo-binstall: -
On Windows, you can use
winget:winget install ctron.oidc -
With
brewto you can: -
With
snapyou can:
Example
Creating a new (confidential) client:
Creating a new (public) client:
Then, get an access token:
Or combine it with e.g., HTTPie:
Or even shorter:
This also works with curl:
MCP Server
oidc-cli includes a built-in MCP server that lets AI assistants retrieve OIDC
tokens for configured clients. This is useful when you want AI-powered tools to make authenticated API calls on your
behalf.
First, set up your OIDC clients as usual (see above). Then start the MCP server:
The server communicates over stdio and exposes two tools:
list_clients— lists all configured OIDC clients with their issuer URL and token statusget_token— retrieves a valid token for a named client, automatically refreshing if expired
Claude Code
To register the MCP server with Claude Code:
More examples
Create a public client from an initial refresh token. This can be useful if you have a frontend application, but no means of performing the authorization code flow with a local server. In case you have access to the refresh token, e.g via the browsers developer console, you can initialize the public client with that: