☥ ANKH
Developer onboarding
Integrate with ANKH using standard OIDC discovery. No proprietary login protocol is required.
1. Choose a client type
Browser/mobile: public OAuth client, no embedded secret, PKCE S256 mandatory. Server applications: confidential client with a one-time displayed secret stored only in the server secret manager.
2. Register exact callbacks
Redirect URIs are exact-match and HTTPS-only, except loopback/localhost development. Production clients should use a stable HTTPS callback.
3. Use discovery + PKCE
GET https://ankhy.app/.well-known/openid-configuration response_type=code code_challenge_method=S256 scope=openid profile state=<random> nonce=<random>
SDKs
- JavaScript/TypeScript:
@ankh/oidc - React:
@ankh/react - Laravel:
ankh/laravel-oidc - WordPress/WooCommerce: ANKH OIDC Login package
All adapters wrap the same standards-native OIDC surface; they do not create a second authentication system.
Go-live checklist
- Validate issuer and JWKS.
- Persist state/nonce/verifier only for the pending transaction.
- Never embed confidential secrets in browser/mobile code.
- Atomically replace refresh tokens after every refresh.
- Provide a tested rollback path before making ANKH the only login route.