V00.77 opt-in module: OAuth2 Relying-Party HTTP flows — authorization-code (+ PKCE), token endpoint with client authentication (basic / post / secret-jwt / private-key-jwt / none), refresh-token rotation with reuse-detection, revocation, introspection and device-authorization grant. JDK HttpClient only; the in-tree JSON scanner parses responses (no JSON library). private_key_jwt / client_secret_jwt sign via the jCustos-jwt JwtSigner. Framework-neutral — no Vaadin / REST ...

Latest Versions

4 versions →
VersionVulnerabilitiesUsagesDate
0.83.x
00.83.00
4
Sep 02, 2026
0.82.x
00.82.00
4
Sep 02, 2026
0.81.x
00.81.20
4
Sep 02, 2026
00.81.10
4
Sep 01, 2026
4 versions →