{
  "info": {
    "name": "Login with idpass — OpenID Connect",
    "description": "Import this to try 'Login with idpass'. Set the collection variables (client_id, client_secret, redirect_uri) from your idpass console, then run the requests top to bottom. Get your keys at https://idpass.in/idpass/signup",
    "schema": "https://schema.getpostman.com/json/collection/v2.1.0/collection.json"
  },
  "variable": [
    { "key": "baseUrl", "value": "https://idpass.in" },
    { "key": "client_id", "value": "idp_YOUR_ID" },
    { "key": "client_secret", "value": "YOUR_SECRET" },
    { "key": "redirect_uri", "value": "https://your-site.com/callback" },
    { "key": "code", "value": "" },
    { "key": "code_verifier", "value": "" },
    { "key": "access_token", "value": "" }
  ],
  "item": [
    {
      "name": "1. Discovery (auto-config)",
      "request": {
        "method": "GET",
        "url": { "raw": "{{baseUrl}}/.well-known/openid-configuration",
          "host": ["{{baseUrl}}"], "path": [".well-known", "openid-configuration"] },
        "description": "The OpenID Connect discovery document. Most libraries only need this URL."
      }
    },
    {
      "name": "2. JWKS (verify tokens)",
      "request": {
        "method": "GET",
        "url": { "raw": "{{baseUrl}}/oidc/jwks.json",
          "host": ["{{baseUrl}}"], "path": ["oidc", "jwks.json"] },
        "description": "Public keys to verify id_token signatures."
      }
    },
    {
      "name": "3. Authorize (open in a browser)",
      "request": {
        "method": "GET",
        "url": {
          "raw": "{{baseUrl}}/oidc/authorize?client_id={{client_id}}&redirect_uri={{redirect_uri}}&response_type=code&scope=openid%20profile&state=xyz&code_challenge=CHALLENGE&code_challenge_method=S256",
          "host": ["{{baseUrl}}"], "path": ["oidc", "authorize"],
          "query": [
            { "key": "client_id", "value": "{{client_id}}" },
            { "key": "redirect_uri", "value": "{{redirect_uri}}" },
            { "key": "response_type", "value": "code" },
            { "key": "scope", "value": "openid profile" },
            { "key": "state", "value": "xyz" },
            { "key": "code_challenge", "value": "CHALLENGE" },
            { "key": "code_challenge_method", "value": "S256" }
          ]
        },
        "description": "OPEN THIS URL IN A BROWSER (not Postman): a QR appears, the user approves in the idpass app, and the browser is redirected to your redirect_uri with ?code=... . Paste that code into the 'code' variable (and the code_verifier you generated) for step 4. Most OIDC libraries build this URL + PKCE for you."
      }
    },
    {
      "name": "4. Token (exchange the code)",
      "request": {
        "method": "POST",
        "header": [{ "key": "Content-Type", "value": "application/x-www-form-urlencoded" }],
        "body": {
          "mode": "urlencoded",
          "urlencoded": [
            { "key": "grant_type", "value": "authorization_code" },
            { "key": "code", "value": "{{code}}" },
            { "key": "redirect_uri", "value": "{{redirect_uri}}" },
            { "key": "client_id", "value": "{{client_id}}" },
            { "key": "client_secret", "value": "{{client_secret}}" },
            { "key": "code_verifier", "value": "{{code_verifier}}" }
          ]
        },
        "url": { "raw": "{{baseUrl}}/oidc/token",
          "host": ["{{baseUrl}}"], "path": ["oidc", "token"] },
        "description": "Returns id_token (the verified identity) + access_token. For public (SPA) apps, omit client_secret."
      }
    },
    {
      "name": "5. UserInfo",
      "request": {
        "method": "GET",
        "header": [{ "key": "Authorization", "value": "Bearer {{access_token}}" }],
        "url": { "raw": "{{baseUrl}}/oidc/userinfo",
          "host": ["{{baseUrl}}"], "path": ["oidc", "userinfo"] },
        "description": "Returns the verified profile for the access_token."
      }
    }
  ]
}
