Skip to content

Get OAuth 2.0 Authorization Server Metadata

GET
/v3/.well-known/oauth-authorization-server
curl --request GET \
--url https://api.hopper.west.prod.govcloud.legion.picogrid.com/v3/.well-known/oauth-authorization-server

Returns OAuth 2.0 authorization server metadata as defined in RFC 8414 by proxying to Keycloak’s well-known endpoint

Successful response

Media typeapplication/json
object
authorization_endpoint
required
string
code_challenge_methods_supported
Array<string>
device_authorization_endpoint
string
grant_types_supported
Array<string>
introspection_endpoint
string
issuer
required
string
jwks_uri
required
string
registration_endpoint
string
request_parameter_supported
boolean
request_uri_parameter_supported
boolean
require_request_uri_registration
boolean
response_modes_supported
Array<string>
response_types_supported
required
Array<string>
revocation_endpoint
string
scopes_supported
Array<string>
token_endpoint
required
string
token_endpoint_auth_methods_supported
Array<string>
Example
{
"authorization_endpoint": "https://auth.legion.com/realms/legion/protocol/openid-connect/auth",
"code_challenge_methods_supported": [
"plain",
"S256"
],
"grant_types_supported": [
"authorization_code",
"refresh_token",
"client_credentials"
],
"introspection_endpoint": "https://auth.legion.com/realms/legion/protocol/openid-connect/token/introspect",
"issuer": "https://auth.legion.com/realms/legion",
"jwks_uri": "https://auth.legion.com/realms/legion/protocol/openid-connect/certs",
"response_types_supported": [
"code",
"id_token",
"token id_token"
],
"revocation_endpoint": "https://auth.legion.com/realms/legion/protocol/openid-connect/revoke",
"scopes_supported": [
"openid",
"profile",
"email",
"offline_access"
],
"token_endpoint": "https://auth.legion.com/realms/legion/protocol/openid-connect/token"
}

Bad Request

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 400,
"details": [
{
"Field": "organization_id",
"Issue": "must be a valid UUID format"
}
],
"message": "Request cannot be processed due to invalid input",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Unauthorized

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 401,
"details": [
{
"Field": "authorization_header",
"Issue": "Bearer token is expired or malformed"
}
],
"message": "Authentication credentials are missing or invalid",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Forbidden

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 403,
"details": [
{
"Field": "required_scope",
"Issue": "requires 'orion:settings:write' scope, but token only has 'orion:settings:read'"
}
],
"message": "Access denied: insufficient permissions for this resource",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Not Found

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 404,
"details": [
{
"Field": "organization_id",
"Issue": "organization with ID 'a1b2c3d4-e5f6-7890-abcd-ef1234567890' not found"
}
],
"message": "The requested resource could not be found",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "req_2J9K8L7M6N5P4Q3R"
}

Internal Server Error

Media typeapplication/json
object
category
required

The category of the error

string
code
required

The HTTP status code

number
details

Additional details about the error

Array<object>
object
field

The field that caused the error

string
issue

The specific issue with the field

string
message
required

A human-readable error message

string
status
required

The status of the response, always ‘error’ for error responses

string
timestamp
required

The timestamp when the error occurred

string format: date-time
trace_id
required

A unique identifier for tracing the error

string format: uuid
Example
{
"category": "server_error",
"code": 500,
"details": [
{
"field": "field_name",
"issue": "Field validation issue"
}
],
"message": "Internal Server Error",
"status": "error",
"timestamp": "2024-03-15T10:30:00Z",
"trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"
}

Bad Gateway

Media typeapplication/json
object
category
required
string
code
required
number
details
Array<object>
object
field
required
string
issue
required
string
message
required
string
status
required
string
timestamp
required
string
trace_id
required
string
Example
{
"code": 500,
"details": [
{
"field": "email",
"issue": "must be a valid email address"
}
],
"message": "External service integration failed",
"status": "error",
"timestamp": "2026-01-15T14:32:45Z",
"trace_id": "b7c5e4d3-a2b1-4f0e-8d9c-1a2b3c4d5e6f"
}

Version 3.14.0 · commit 0771262