ClemSSO

OAuth 2.0 / OpenID Connect identity provider.

Public Keys

Public clients authenticate with PKCE. No client secret required.

Dev & Prod Keys

Separate keys for development and production. Dev keys allow localhost.

Per-App Identifiers

The protected_sub scope returns a per-app user ID, not the global UUID.