Validate provider ID tokens and issue your own access/refresh JWTs
1.5K
Validate ID tokens from third-party OIDC providers (Google, Apple, …) and exchange them for self-issued access and refresh tokens — a single Rust binary that runs as a long-lived HTTP server (or an AWS Lambda function).
Multi-arch (linux/amd64, linux/arm64), published to both registries:
antstanley80/oidc-exchangeghcr.io/antstanley/oidc-exchangeTags: latest, X.Y.Z, X.Y, X.
The GHCR multi-arch tag has build provenance for its immutable final manifest digest (in addition to each platform digest). Verify the final GHCR manifest before running it:
gh attestation verify oci://ghcr.io/antstanley/oidc-exchange:latest \
--repo antstanley/oidc-exchange \
--signer-workflow antstanley/oidc-exchange/.github/workflows/release.yml
docker pull ghcr.io/antstanley/oidc-exchange:latest
This is GitHub build provenance, not a registry signature. The release is also copied to Docker Hub, but the workflow does not attach or promise a Docker Hub-verifiable attestation; use GHCR for this verification path.
docker run -p 8080:8080 \
-v "$(pwd)/config.toml:/app/config.toml:ro" \
antstanley80/oidc-exchange:latest
The server listens on the port from your config (default 8080) and exposes /token, /revoke, /keys, /.well-known/openid-configuration, and /health.
Mount a config.toml (as above) and/or override values with environment variables (OIDC_EXCHANGE__{section}__{key}); ${VAR} placeholders in the TOML resolve from the environment. Minimal example:
[server]
host = "0.0.0.0"
port = 8080
issuer = "https://auth.example.com"
[providers.google]
adapter = "oidc"
issuer = "https://accounts.google.com"
client_id = "${GOOGLE_CLIENT_ID}"
client_secret = "${GOOGLE_CLIENT_SECRET}"
# Origins Google's discovery document may name beyond the issuer's origin:
endpoint_origins = ["https://oauth2.googleapis.com", "https://www.googleapis.com"]
endpoint_origins pins which origins a provider's discovery document is allowed to name; each entry must be a bare https://host[:port], and an unpinned origin logs a warning when discovered.
See the full configuration guide and the deployment guides (ECS Fargate, generic container / Kubernetes, …).
Images are built multi-arch on native runners and published from CI. MIT licensed.
Content type
Image
Digest
sha256:a505cdc38…
Size
49.1 MB
Last updated
about 1 month ago
docker pull antstanley80/oidc-exchange