Ignis.Auth
OAuth 2.0 authorization server built on OpenIddict with MongoDB storage. Supports client_credentials and authorization_code (with mandatory PKCE + PAR) grant types.
Configuration
{"AuthSettings": {"ConnectionString": "mongodb://localhost:27017/ignis","Clients": [{"ClientId": "my-backend","ClientSecret": "my-secret","DisplayName": "Backend Service","AllowedGrantTypes": ["client_credentials"]},{"ClientId": "my-web-app","ClientSecret": "web-secret","DisplayName": "My Web App","AllowedGrantTypes": ["authorization_code"],"RedirectUris": ["https://app.example.com/callback"],"PostLogoutRedirectUris": ["https://app.example.com"]}],"Endpoints": {"LoginPath": "connect/login"},"Certificates": {"SigningCertificatePath": "certs/signing.pfx","SigningCertificatePassword": "","EncryptionCertificatePath": "certs/encryption.pfx","EncryptionCertificatePassword": ""}}}
All clients are confidential and require a ClientSecret. AllowedGrantTypes is required.
Certificates
Development mode uses ephemeral auto-generated certificates. For production, generate PFX certificates:
mkdir -p certsfor NAME in signing encryption; doopenssl req -x509 -nodes -newkey rsa:2048 \-keyout certs/$NAME-key.pem -out certs/$NAME-cert.pem \-days 365 -subj "/CN=Ignis ${NAME^}"openssl pkcs12 -export -out certs/$NAME.pfx \-inkey certs/$NAME-key.pem -in certs/$NAME-cert.pem -passout pass:donerm certs/*.pem
The certs/ directory is gitignored. Mount via volume or secrets in production.
External identity providers
The authorization code flow requires an external identity provider for user login. Providers are configured via ExternalProviders in AuthSettings with a Type enum (GitHub, OIDC).
See Authentication for the overall flow and Authenticate with GitHub for a complete GitHub setup guide.
Client sync
Clients in AuthSettings.Clients are synced to MongoDB on startup — created, updated, or removed to match configuration.