# Goiabada > An open-source OAuth2 and OpenID Connect server for simple, secure authentication. Every page below, in full and as Markdown, is in one file: [llms-full.txt](https://goiabada.dev/llms-full.txt) ## Get started - [Introduction](https://goiabada.dev/get-started/introduction/): What Goiabada is, what it does for your apps, and how its parts fit together. - [Quickstart](https://goiabada.dev/get-started/quickstart/): Run Goiabada on your own machine in a few minutes, to try it out. - [First sign-in](https://goiabada.dev/get-started/first-sign-in/): Sign in to the admin console for the first time, and the three things worth doing right after. ## Guides - [Add sign-in to a web app](https://goiabada.dev/guides/add-sign-in-to-a-web-app/): Let users sign in to a web app that runs on a server, with the authorization code flow and PKCE. - [Add sign-in to a SPA or mobile app](https://goiabada.dev/guides/add-sign-in-to-a-spa-or-mobile-app/): Let users sign in to a single-page app, a mobile app or a desktop app, which can't keep a secret. - [Sign users out](https://goiabada.dev/guides/sign-users-out/): Sign a user out of your app and of the auth server, and bring them back to your app afterwards. - [Protect an API](https://goiabada.dev/guides/protect-an-api/): Decide who may call your API, and check the access token on every request, for users and for services. - [Require two-factor authentication](https://goiabada.dev/guides/require-two-factor-authentication/): Make users enter a one-time code from an authenticator app as well as their password, for your app or for the admin console. - [Single sign-on across clients](https://goiabada.dev/guides/single-sign-on-across-clients/): Let a user who signed in to one of your apps go straight into the others, and sign them out of each. - [Let clients register themselves (DCR)](https://goiabada.dev/guides/let-clients-register-themselves-dcr/): Turn on dynamic client registration so tools such as MCP clients can register themselves, and review what registered. - [Customize and translate the pages](https://goiabada.dev/guides/customize-and-translate-the-pages/): Put your name and colors on the sign-in pages and the admin console, add a language, reword any text, and change the templates. ## Concepts - [Clients](https://goiabada.dev/concepts/clients/): Register your app as a client, and choose how it signs users in and what it may ask for. - [Users and groups](https://goiabada.dev/concepts/users-and-groups/): Create users, organize them in groups, and give them permissions and attributes. - [Self-registration](https://goiabada.dev/concepts/self-registration/): Let people create their own accounts from the sign-in page, with or without email verification. - [Password recovery](https://goiabada.dev/concepts/password-recovery/): How a user who forgot their password gets a reset link, and what that link can and can't do. - [Resources and permissions](https://goiabada.dev/concepts/resources-and-permissions/): Describe what your APIs protect, and decide which users, groups and clients may do what. - [Scopes](https://goiabada.dev/concepts/scopes/): What your app can ask for, which claims each scope gives it, and where those claims appear. - [Tokens](https://goiabada.dev/concepts/tokens/): What your app gets when a user signs in, what's in each token, how long it lasts, and how to check one. - [Refresh tokens](https://goiabada.dev/concepts/refresh-tokens/): Get new tokens without asking the user to sign in again, and keep your app's refresh token working. - [Sessions](https://goiabada.dev/concepts/sessions/): How single sign-on works, how long a session lasts, and how to ask a user to sign in again. - [Ending sessions](https://goiabada.dev/concepts/ending-sessions/): End a user's session, and know what ending one, signing out, a credential change or another user signing in revokes. - [ACR and AMR](https://goiabada.dev/concepts/acr-and-amr/): Choose how strongly users sign in to your app, and read how they did from the acr and amr claims. - [prompt](https://goiabada.dev/concepts/prompt/): Check for a session without showing the user anything, always ask for their password, or always show the consent screen. - [id_token_hint](https://goiabada.dev/concepts/id-token-hint/): Tell the auth server which user your app expects, so a sign-in never comes back for someone else. - [PKCE](https://goiabada.dev/concepts/pkce/): Tie each authorization code to the app that asked for it, so a stolen code can't be redeemed. - [Audit log](https://goiabada.dev/concepts/audit-log/): See who signed in, what changed and what was refused, and alert on the events that matter. - [Glossary](https://goiabada.dev/concepts/glossary/): The words the docs use, what each one means, and the one name each concept goes by. ## Deploy - [Choose a method](https://goiabada.dev/deploy/choose-a-method/): Compare the ways to run Goiabada in production, by how each handles TLS, what it exposes and what it suits. - [Setup wizard](https://goiabada.dev/deploy/setup-wizard/): Generate a ready-to-run configuration for Docker Compose, Kubernetes or the native binaries, with every key and password created for you. - [Docker Compose](https://goiabada.dev/deploy/docker-compose/): Run the Docker Compose files the setup wizard generates for production, and what they set up. - [Cloudflare Tunnel](https://goiabada.dev/deploy/cloudflare-tunnel/): Run Goiabada with Docker Compose behind a Cloudflare Tunnel, with no open port and no certificate to manage. - [Cloudflare + Nginx](https://goiabada.dev/deploy/cloudflare-nginx/): Run Goiabada with Docker Compose behind Nginx on a server that Cloudflare's proxy fronts. - [Reverse proxy](https://goiabada.dev/deploy/reverse-proxy/): Run Goiabada with Docker Compose behind Nginx on the same host, with Let's Encrypt certificates. - [Overview](https://goiabada.dev/deploy/kubernetes/overview/): What Goiabada needs from a Kubernetes cluster, what the setup wizard's manifest runs, and the order to set it up in. - [Gateway and certificates](https://goiabada.dev/deploy/kubernetes/gateway-and-certificates/): Install Envoy Gateway and cert-manager on a Kubernetes cluster, then deploy Goiabada behind them with HTTPS. - [High availability](https://goiabada.dev/deploy/kubernetes/high-availability/): Run more than one Goiabada pod on Kubernetes, size the database's connections for them, and keep serving through drains and rollouts. - [Security](https://goiabada.dev/deploy/kubernetes/security/): The pod security Goiabada's Kubernetes manifest sets, the NetworkPolicies that decide who reaches its pods, how to encrypt the hop to the auth server, and where the database's certificate authority lives. - [Secrets](https://goiabada.dev/deploy/kubernetes/secrets/): The Kubernetes Secrets Goiabada's manifest reads, the ways to create them, who can read the AES key, and rotating Secrets another tool owns. - [Probes and shutdown](https://goiabada.dev/deploy/kubernetes/probes-and-shutdown/): What Goiabada's health endpoint tells Kubernetes, how long a pod may take to start, and how it stops within its grace period. - [Native binaries](https://goiabada.dev/deploy/native-binaries/): Run the auth server and the admin console as two processes on your own server, without Docker. - [Client IP and proxy trust](https://goiabada.dev/deploy/client-ip-and-proxy-trust/): Make Goiabada see each client's own IP address behind a reverse proxy, a Cloudflare Tunnel, Cloudflare and Nginx, or a Kubernetes gateway. - [Database](https://goiabada.dev/deploy/database/): Prepare the database Goiabada stores everything in, on PostgreSQL, MySQL, SQL Server or SQLite, and run it with a least-privilege login. - [Secrets](https://goiabada.dev/deploy/secrets/): What each of Goiabada's secrets protects, where your setup keeps them, and how to back up the AES key. - [Rotate secrets](https://goiabada.dev/deploy/rotate-secrets/): Replace the session keys, the AES key, the database password and the admin console's client secret, each with as little disruption as it allows. - [Upgrade Goiabada](https://goiabada.dev/deploy/upgrade-goiabada/): Update a deployment to a new release, what the auth server does to the database schema when it starts, and how to roll back. - [Monitoring](https://goiabada.dev/deploy/monitoring/): Turn on Goiabada's Prometheus metrics, scrape them on Kubernetes or anywhere else, and alert on what matters. - [Logs](https://goiabada.dev/deploy/logs/): Collect Goiabada's logs, find the records worth knowing, and see what the logs leave out. - [Production checklist](https://goiabada.dev/deploy/production-checklist/): What to check before a Goiabada deployment goes live, with a link to where each item is explained. ## Reference - [Authorize](https://goiabada.dev/reference/endpoints/authorize/): Send a user to sign in at /auth/authorize, and read the code or the error that comes back. - [Token](https://goiabada.dev/reference/endpoints/token/): Exchange an authorization code for tokens, refresh them, or get a client's own token at POST /auth/token. - [Logout](https://goiabada.dev/reference/endpoints/logout/): Sign a user out of the auth server from your app with /auth/logout, and bring them back. - [UserInfo](https://goiabada.dev/reference/endpoints/userinfo/): Read the signed-in user's claims from /userinfo with their access token. - [Dynamic client registration](https://goiabada.dev/reference/endpoints/dynamic-client-registration/): Let an app register itself as a client with POST /connect/register. - [Discovery and JWKS](https://goiabada.dev/reference/endpoints/discovery-and-jwks/): Read the auth server's endpoints and capabilities from its discovery document, and the keys that check its tokens' signatures from /certs. - [Logo and picture](https://goiabada.dev/reference/endpoints/logo-and-picture/): Show a client's logo or a user's profile picture from the auth server's two public image endpoints. - [Authentication](https://goiabada.dev/reference/api/authentication/): Get an access token and call the Admin API or the Account API with it. - [Scopes](https://goiabada.dev/reference/api/scopes/): Which scope each Admin API and Account API operation accepts, and how to pick the smallest one that does the job. - [Administrators](https://goiabada.dev/reference/api/administrators/): Who counts as an administrator, why only authserver:manage can change one, and what the API answers when another scope tries. - [Errors](https://goiabada.dev/reference/api/errors/): The format of every Admin API and Account API error answer, and what its error codes mean. - [Overview](https://goiabada.dev/reference/api/admin/): The REST API of the Goiabada auth server. - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/users/): User management (Admin API) - [Search users](https://goiabada.dev/reference/api/admin/operations/searchusers/): Search for users with pagination. - [Create user](https://goiabada.dev/reference/api/admin/operations/createuser/): Create a new user as admin - [Get user](https://goiabada.dev/reference/api/admin/operations/getuser/): Get one user’s own fields: profile, email, phone, address and whether OTP is enabled. - [Delete user](https://goiabada.dev/reference/api/admin/operations/deleteuser/): Delete a user by ID - [Update user profile](https://goiabada.dev/reference/api/admin/operations/updateuserprofile/): Update user profile information - [Update user email](https://goiabada.dev/reference/api/admin/operations/updateuseremail/): Update user email address and verification status. - [Generate email verification code](https://goiabada.dev/reference/api/admin/operations/generateuseremailverificationcode/): Generate a new email verification code for a user and return it in the response. - [Update user phone](https://goiabada.dev/reference/api/admin/operations/updateuserphone/): Update user phone number - [Update user address](https://goiabada.dev/reference/api/admin/operations/updateuseraddress/): Update user address information - [Update user password](https://goiabada.dev/reference/api/admin/operations/updateuserpassword/): Set a new password for the user - [Enable/disable user](https://goiabada.dev/reference/api/admin/operations/updateuserenabled/): Enable or disable a user account - [Disable user OTP](https://goiabada.dev/reference/api/admin/operations/updateuserotp/): Disable OTP (two-factor authentication) for a user. - [Get user profile picture info](https://goiabada.dev/reference/api/admin/operations/getuserprofilepictureinfo/): Check whether a user has a profile picture and get the picture URL - [Upload user profile picture](https://goiabada.dev/reference/api/admin/operations/uploaduserprofilepicture/): Upload or replace the user’s profile picture. - [Delete user profile picture](https://goiabada.dev/reference/api/admin/operations/deleteuserprofilepicture/): Remove the user’s profile picture - [Get user groups](https://goiabada.dev/reference/api/admin/operations/getusergroups/): Get groups that a user belongs to - [Set user groups](https://goiabada.dev/reference/api/admin/operations/updateusergroups/): Replace all groups for a user - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/user-attributes/): Custom user attributes (Admin API) - [List user attributes](https://goiabada.dev/reference/api/admin/operations/getuserattributes/): Get all custom attributes for a user - [Create user attribute](https://goiabada.dev/reference/api/admin/operations/createuserattribute/): Create a new custom attribute for a user - [Get user attribute](https://goiabada.dev/reference/api/admin/operations/getuserattribute/): Get a specific user attribute by ID - [Update user attribute](https://goiabada.dev/reference/api/admin/operations/updateuserattribute/): Update a user attribute - [Delete user attribute](https://goiabada.dev/reference/api/admin/operations/deleteuserattribute/): Delete a user attribute - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/user-sessions/): User session management (Admin API) - [List user sessions](https://goiabada.dev/reference/api/admin/operations/getusersessions/): Get the user’s live sessions, each with its device, IP address and the identifiers of the clients it authorized. - [Get session](https://goiabada.dev/reference/api/admin/operations/getusersession/): Get session details by identifier - [Delete session](https://goiabada.dev/reference/api/admin/operations/deleteusersession/): Terminate a user session. - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/user-consents/): OAuth consent management (Admin API) - [List user consents](https://goiabada.dev/reference/api/admin/operations/getuserconsents/): Get all OAuth consents granted by a user - [Revoke consent](https://goiabada.dev/reference/api/admin/operations/deleteuserconsent/): Revoke an OAuth consent - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/groups/): Group management (Admin API) - [List groups](https://goiabada.dev/reference/api/admin/operations/getgroups/): Get all groups - [Create group](https://goiabada.dev/reference/api/admin/operations/creategroup/): Create a new group - [Search groups annotated with a permission](https://goiabada.dev/reference/api/admin/operations/searchgroupswithpermissionannotation/): Get a page of groups, each annotated with whether it has the given permission assigned. - [Get group](https://goiabada.dev/reference/api/admin/operations/getgroup/): Get group details by ID - [Update group](https://goiabada.dev/reference/api/admin/operations/updategroup/): Update group details - [Delete group](https://goiabada.dev/reference/api/admin/operations/deletegroup/): Delete a group - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/group-members/): Group membership management (Admin API) - [List group members](https://goiabada.dev/reference/api/admin/operations/getgroupmembers/): Get members of a group with pagination - [Add group member](https://goiabada.dev/reference/api/admin/operations/addgroupmember/): Add a user to a group - [Remove group member](https://goiabada.dev/reference/api/admin/operations/removegroupmember/): Remove a user from a group - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/group-attributes/): Custom group attributes (Admin API) - [List group attributes](https://goiabada.dev/reference/api/admin/operations/getgroupattributes/): Get all custom attributes for a group - [Create group attribute](https://goiabada.dev/reference/api/admin/operations/creategroupattribute/): Create a new custom attribute for a group - [Get group attribute](https://goiabada.dev/reference/api/admin/operations/getgroupattribute/): Get a specific group attribute by ID - [Update group attribute](https://goiabada.dev/reference/api/admin/operations/updategroupattribute/): Update a group attribute - [Delete group attribute](https://goiabada.dev/reference/api/admin/operations/deletegroupattribute/): Delete a group attribute - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/resources/): Resource management (Admin API) - [List resources](https://goiabada.dev/reference/api/admin/operations/getresources/): Get all resources - [Create resource](https://goiabada.dev/reference/api/admin/operations/createresource/): Create a new resource - [Get resource](https://goiabada.dev/reference/api/admin/operations/getresource/): Get resource details by ID - [Update resource](https://goiabada.dev/reference/api/admin/operations/updateresource/): Update resource details - [Delete resource](https://goiabada.dev/reference/api/admin/operations/deleteresource/): Delete a resource - [Get resource permissions](https://goiabada.dev/reference/api/admin/operations/getresourcepermissions/): Get permissions defined for a resource - [Update resource permissions](https://goiabada.dev/reference/api/admin/operations/updateresourcepermissions/): Replace the permissions of a resource. - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/permissions/): Permission management (Admin API) - [Get user permissions](https://goiabada.dev/reference/api/admin/operations/getuserpermissions/): Get permissions assigned to a user - [Set user permissions](https://goiabada.dev/reference/api/admin/operations/updateuserpermissions/): Replace all permissions for a user - [Get group permissions](https://goiabada.dev/reference/api/admin/operations/getgrouppermissions/): Get permissions assigned to a group - [Set group permissions](https://goiabada.dev/reference/api/admin/operations/updategrouppermissions/): Replace all permissions for a group - [Get users with permission](https://goiabada.dev/reference/api/admin/operations/getusersbypermission/): Get users that have a specific permission - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/clients/): OAuth client management (Admin API) - [List clients](https://goiabada.dev/reference/api/admin/operations/getclients/): Get all OAuth2/OIDC clients - [Create client](https://goiabada.dev/reference/api/admin/operations/createclient/): Create a new OAuth2/OIDC client - [Get client](https://goiabada.dev/reference/api/admin/operations/getclient/): Get client details by ID. - [Update client settings](https://goiabada.dev/reference/api/admin/operations/updateclientsettings/): Update client general settings - [Delete client](https://goiabada.dev/reference/api/admin/operations/deleteclient/): Delete an OAuth2/OIDC client. - [Get client secret](https://goiabada.dev/reference/api/admin/operations/getclientsecret/): Get a client’s secret, decrypted. - [Update client authentication](https://goiabada.dev/reference/api/admin/operations/updateclientauthentication/): Update client public/confidential mode and secret. - [Update OAuth2 flows](https://goiabada.dev/reference/api/admin/operations/updateclientoauth2flows/): Enable/disable OAuth2 flows for a client - [Update redirect URIs](https://goiabada.dev/reference/api/admin/operations/updateclientredirecturis/): Replace redirect URIs for a client - [Update web origins](https://goiabada.dev/reference/api/admin/operations/updateclientweborigins/): Replace web origins for a client - [Update token settings](https://goiabada.dev/reference/api/admin/operations/updateclienttokens/): Update token expiration settings for a client. - [Get client permissions](https://goiabada.dev/reference/api/admin/operations/getclientpermissions/): Get permissions assigned to a client - [Set client permissions](https://goiabada.dev/reference/api/admin/operations/updateclientpermissions/): Replace all permissions for a client - [Switch whether a client may request the administrative scopes](https://goiabada.dev/reference/api/admin/operations/updateclientadministrativescopes/): Switch whether the client may request the six administrative authserver scopes (manage, admin-read, manage-users, manage-clients, manage-settings and browser-sessions) on a user’s behalf, through the authorization code, implicit, refresh token and password grants. - [List client sessions](https://goiabada.dev/reference/api/admin/operations/getclientsessions/): Get a page of the user sessions associated with a client, together with the people they belong to. - [Get client logo info](https://goiabada.dev/reference/api/admin/operations/getclientlogoinfo/): Check if a client has a logo and get the logo URL - [Upload client logo](https://goiabada.dev/reference/api/admin/operations/uploadclientlogo/): Upload or replace the client logo image. - [Delete client logo](https://goiabada.dev/reference/api/admin/operations/deleteclientlogo/): Remove the client logo - [Get client logo image](https://goiabada.dev/reference/api/admin/operations/getclientlogoimage/): Serve the client logo image. - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/audit-logs/): Audit log query (Admin API) - [Query audit logs](https://goiabada.dev/reference/api/admin/operations/getauditlogs/): Get a page of audit log entries, most recent first, optionally narrowed to a single audit event, a single request id, or both. - [Get audit event types](https://goiabada.dev/reference/api/admin/operations/getauditeventtypes/): Get the catalog of audit event names this server can write, which is the set the auditEvent filter on GET /api/v1/admin/audit-logs accepts. - [Overview](https://goiabada.dev/reference/api/admin/operations/tags/settings/): System settings (Admin API) - [Get general settings](https://goiabada.dev/reference/api/admin/operations/getsettingsgeneral/): Get general system settings - [Update general settings](https://goiabada.dev/reference/api/admin/operations/updatesettingsgeneral/): Update general system settings - [Get email settings](https://goiabada.dev/reference/api/admin/operations/getsettingsemail/): Get SMTP/email settings. - [Update email settings](https://goiabada.dev/reference/api/admin/operations/updatesettingsemail/): Update SMTP/email settings. - [Send test email](https://goiabada.dev/reference/api/admin/operations/sendtestemail/): Send a short message to to through the stored SMTP settings, the stored password included, to check what a save’s connection does not: the encryption, the certificate, the credentials and the sender. - [Get session settings](https://goiabada.dev/reference/api/admin/operations/getsettingssessions/): Get session timeout settings - [Update session settings](https://goiabada.dev/reference/api/admin/operations/updatesettingssessions/): Update session timeout settings - [Get UI theme](https://goiabada.dev/reference/api/admin/operations/getsettingsuitheme/): Get current UI theme and available themes - [Update UI theme](https://goiabada.dev/reference/api/admin/operations/updatesettingsuitheme/): Update UI theme - [Get token settings](https://goiabada.dev/reference/api/admin/operations/getsettingstokens/): Get default token expiration settings - [Update token settings](https://goiabada.dev/reference/api/admin/operations/updatesettingstokens/): Update default token expiration settings - [Get audit log settings](https://goiabada.dev/reference/api/admin/operations/getsettingsauditlogs/): Get audit log destinations and retention - [Update audit log settings](https://goiabada.dev/reference/api/admin/operations/updatesettingsauditlogs/): Update audit log destinations and retention. - [Get signing keys](https://goiabada.dev/reference/api/admin/operations/getsettingskeys/): Get all signing keys (public key material only) - [Rotate signing keys](https://goiabada.dev/reference/api/admin/operations/rotatesettingskeys/): Generate a new signing key. - [Delete signing key](https://goiabada.dev/reference/api/admin/operations/deletesettingskey/): Delete a signing key - [Get phone countries](https://goiabada.dev/reference/api/admin/operations/getphonecountries/): Get the list of countries with their calling codes. - [Overview](https://goiabada.dev/reference/api/account/): The REST API of the Goiabada auth server. - [Get own profile](https://goiabada.dev/reference/api/account/operations/getaccountprofile/): Get the authenticated user’s profile - [Update own profile](https://goiabada.dev/reference/api/account/operations/updateaccountprofile/): Update the authenticated user’s profile - [Update own email](https://goiabada.dev/reference/api/account/operations/updateaccountemail/): Update the authenticated user’s email (marks as unverified). - [Send verification email](https://goiabada.dev/reference/api/account/operations/sendaccountemailverification/): Send an email verification code to the account’s address. - [Verify email](https://goiabada.dev/reference/api/account/operations/verifyaccountemail/): Verify the account’s address with the code sendAccountEmailVerification sent: 8 characters, four letters then four digits, compared without regard to case, valid for 5 minutes. - [Update own phone](https://goiabada.dev/reference/api/account/operations/updateaccountphone/): Update the authenticated user’s phone number - [Update own address](https://goiabada.dev/reference/api/account/operations/updateaccountaddress/): Update the authenticated user’s address - [Change own password](https://goiabada.dev/reference/api/account/operations/updateaccountpassword/): Change the password. - [Get own profile picture info](https://goiabada.dev/reference/api/account/operations/getaccountprofilepictureinfo/): Check whether the authenticated user has a profile picture and get the picture URL - [Upload own profile picture](https://goiabada.dev/reference/api/account/operations/uploadaccountprofilepicture/): Upload or replace the authenticated user’s profile picture. - [Delete own profile picture](https://goiabada.dev/reference/api/account/operations/deleteaccountprofilepicture/): Remove the authenticated user’s profile picture - [Start OTP enrollment](https://goiabada.dev/reference/api/account/operations/getaccountotpenrollment/): Issues the TOTP enrollment for the authenticated user and returns the QR code and secret to set up an authenticator with. - [Enable/disable OTP](https://goiabada.dev/reference/api/account/operations/updateaccountotp/): Enables or disables TOTP for the authenticated user. - [List own consents](https://goiabada.dev/reference/api/account/operations/getaccountconsents/): Get all OAuth consents granted by the authenticated user - [Revoke own consent](https://goiabada.dev/reference/api/account/operations/deleteaccountconsent/): Revoke an OAuth consent - [List own sessions](https://goiabada.dev/reference/api/account/operations/getaccountsessions/): Get the caller’s live sessions, each with its device, IP address and the identifiers of the clients it authorized. - [Terminate own session](https://goiabada.dev/reference/api/account/operations/deleteaccountsession/): Terminate one of the caller’s own sessions, the current one included. - [Prepare a sign-out](https://goiabada.dev/reference/api/account/operations/requestaccountlogout/): Validate the sign-out target, mint a short-lived id_token_hint and return the prepared sign-out operation, as either a self-submitting form’s parameters or a URL to follow. - [Environment variables](https://goiabada.dev/reference/environment-variables/): Every setting the auth server and the admin console read, with its flag, its default and which server reads it. - [Security](https://goiabada.dev/reference/security/): Report a vulnerability, and see how Goiabada protects sign-ins, tokens, sessions and the data it stores. ## Troubleshooting - [Invalid redirect_uri](https://goiabada.dev/troubleshooting/invalid-redirect-uri/): The sign-in stops on "Unable to authorize" with "Invalid redirect_uri parameter", or the token endpoint answers "Invalid redirect_uri." - [The app gets no error back](https://goiabada.dev/troubleshooting/the-app-gets-no-error-back/): A sign-in fails, and your app never receives the error response it expects at its redirect URI. - [invalid_scope](https://goiabada.dev/troubleshooting/invalid-scope/): A request is refused with invalid_scope, or a token comes back without a scope your app asked for. - [login_required](https://goiabada.dev/troubleshooting/login-required/): A silent request with prompt=none, or a request with an id_token_hint, comes back with error=login_required. - [This refresh token has been revoked](https://goiabada.dev/troubleshooting/this-refresh-token-has-been-revoked/): A refresh answers invalid_grant, and the refresh token your app just got stops working too. - [Sign-out answers 403](https://goiabada.dev/troubleshooting/sign-out-answers-403/): A POST to /auth/logout answers 403 Forbidden with "Your request was refused for security reasons." - [Too many attempts or 429](https://goiabada.dev/troubleshooting/too-many-attempts-or-429/): A sign-in page says "Too many attempts", or an endpoint answers 429 Too Many Requests. - [Locked out of the admin console](https://goiabada.dev/troubleshooting/locked-out-of-the-admin-console/): The admin console can't sign you in, or nobody who can manage Goiabada can sign in any more. - [Unable to load the configuration from the auth server](https://goiabada.dev/troubleshooting/unable-to-load-the-configuration-from-the-auth-server/): Every admin console page answers 500 with "Unable to load the configuration from the auth server", or signing in fails. - [A user cannot reset their password](https://goiabada.dev/troubleshooting/a-user-cannot-reset-their-password/): No "Forgot password?" link, no reset email, or a reset link that says the verification code is invalid or expired. - [Certificates are not issued](https://goiabada.dev/troubleshooting/certificates-are-not-issued/): On Kubernetes, the Gateway's certificates stay not ready, so the auth server and the admin console don't answer over HTTPS. - [CrashLoopBackOff or unable to create the database connection](https://goiabada.dev/troubleshooting/crashloopbackoff-or-unable-to-create-the-database-connection/): The auth server's pod crash-loops, or its container keeps restarting, because it can't reach the database or refuses its configuration. - [Database TLS connection fails](https://goiabada.dev/troubleshooting/database-tls-connection-fails/): Fix a database connection refused because TLS or the database's certificate doesn't meet the auth server's settings. - [PostgreSQL TLS variables stop startup](https://goiabada.dev/troubleshooting/postgresql-tls-variables/): Fix a PostgreSQL startup refusal caused by PGSSL environment variables. - [attempt to write a readonly database](https://goiabada.dev/troubleshooting/attempt-to-write-a-readonly-database/): The auth server on SQLite stops at start with "attempt to write a readonly database", usually after a new image or a move to another user. - [Waiting for the migration lock, or marked dirty](https://goiabada.dev/troubleshooting/waiting-for-the-migration-lock-or-marked-dirty/): A start waits at "waiting for the migration lock", or refuses a database that is marked dirty or that a newer release migrated. - [Metrics are not scraped](https://goiabada.dev/troubleshooting/metrics-are-not-scraped/): Prometheus or another scraper shows Goiabada's targets down, or doesn't list them at all. ## Legacy flows - [Implicit flow](https://goiabada.dev/legacy-flows/implicit/): The deprecated implicit flow, which hands tokens to the browser in the redirect. When to turn it on, how it works, and how to move off it. - [Resource Owner Password Credentials (ROPC)](https://goiabada.dev/legacy-flows/ropc/): The deprecated password grant, where an app sends a user's email and password to the token endpoint. When to turn it on, how it works, and what to use instead. ## About - [About](https://goiabada.dev/about/): Why Goiabada exists, where its name comes from, who makes it, and how to get in touch. - [Contributing](https://goiabada.dev/about/contributing/): Set up the dev container, run Goiabada from source, run the tests and send a change. - [License](https://goiabada.dev/about/license/): Goiabada is free and open source under the MIT License. ## Other pages - [Welcome](https://goiabada.dev/): An open-source OAuth2 and OpenID Connect server for simple, secure authentication.