Upstream Identity Provider Infrastructure

Canonical OIDC authority and shared authentication foundation for the AI stack. Provides cryptographic token issuance, JWKS discovery, and deterministic account mapping across all fleet workloads.

System State Active Identity Gateway v26.7.3
Authoritative Issuer https://eyedbase.com Realm: ai-stack
Active Pilot Clients 3 Registered EyeParity · DevOps · Fleet
OIDC Discovery HTTP 200 OK RFC 8414 Verified
Operational Protocols & Service Matrix
ID-01 / ID-04 Specification
Component / Capability Standard / Protocol Audience / Scope Enforcement Policy Status
OpenID Discovery RFC 8414 / OpenID Core 1.0 /.well-known/openid-configuration Public Cached Metadata ACTIVE
Cryptographic Keyset RFC 7517 / RS256 eyedbase-ai-stack-2026-v1 Hardware-Bound Verification ACTIVE
Browser Authentication Authorization Code + PKCE S256 Code Challenge Password Grant Prohibited ENFORCED
Workload Identities OAuth 2.0 Client Credentials product:resource:action Least-Privilege Scoping PROVISIONED
Account Reconciliation ID-05 Deterministic Mapping (issuer, subject, product) Anti-Silent Takeover LOCKED
Registered Product Pilot Clients
3 Product Integrations
Client ID Product Target Flow Type Callback URL State
eye-parity-prod-client EyeParity Visual QA Authorization Code (S256) https://app.eyeparity.com/api/auth/oidc/callback CONFIDENTIAL
devops-manager-prod-client DevOps Manager (MechScrum) Authorization Code (S256) https://devops-manager.agiledatasolution.com/callback CONFIDENTIAL
fleetboots-prod-client Fleet Manager (FleetBoots) Client Credentials Machine Principal / Server-to-Server SCOPED
Canonical Identity Endpoints (OpenID Connect)
RFC 8414 Discovery
OIDC Configuration Metadata
https://eyedbase.com/.well-known/openid-configuration
JWKS Public Certificates
https://eyedbase.com/realms/ai-stack/protocol/openid-connect/certs
OAuth 2.0 Token Exchange
https://eyedbase.com/realms/ai-stack/protocol/openid-connect/token
User Authorization Endpoint
https://eyedbase.com/realms/ai-stack/protocol/openid-connect/auth