OIDC & Identity Broker Configuration
Configure OAuth2 PKCE authorization flows, ZDR verification scopes, and token exchange gateways.
Verified Claims & OIDC Discovery Metadata
Token Handshake
18.5 ms
Security Tier
FIPS 140-3
ZDR Attestation
Cryptographic
Click "Generate Identity Gateway Config" to compile OIDC provider metadata...
ChatGPT Identity Gateway Topology
Overview & Production Standards
"Sign in with ChatGPT" allows enterprise platforms, internal tooling, and B2B SaaS products to leverage OpenAI's verified identity credentials. Rather than managing independent user credentials, apps receive signed JWTs with explicit Zero Data Retention (ZDR) policy flags and agent delegation scopes.
Enterprise Production Scenarios
- Zero-Trust Internal Developer Portals: Authenticate engineers using their enterprise ChatGPT credentials, inheriting corporate organization entitlements.
- Agent Impersonation & Delegation Control: Grant autonomous agents ephemeral user delegation tokens that strictly expire upon task completion.
- Single-Sign-On for Multi-Tenant AI Applications: Seamlessly onboard enterprise teams with instant OAuth2 authorization and SCIM group mapping.
Infrastructure & Software Technology Stack
Infrastructure Stack
- Orchestration: Kubernetes Deployment & ClusterIP Service
- Ingress & Gateway: Envoy Proxy / Traefik with TLS 1.3 termination
- Container Engine: Docker OCI Distroless Python 3.11 Runtime
- Session Cache: Redis 7.2 Cluster (Ephemeral token & JWKS cache)
- Zero-Trust Mesh: Cloudflare Access & Istio mTLS Policy
Software & Frameworks
- API Framework: FastAPI 0.110+ (Asynchronous ASGI Router)
- Cryptographic Core: PyJWT 2.8+ & Cryptography (RS256 Signature)
- Data Contracts: Pydantic v2 (Strict ZDR Claims Validation)
- HTTP Engine: HTTPX / AsyncIO Non-blocking Connection Pooling
- Web Application: Vanilla JS / ES Modules (Zero Build Overhead)
Identity & Auth Protocols
- Protocol: OpenID Connect (OIDC Core 1.0) & OAuth 2.0 (RFC 6749)
- Handshake Security: PKCE with SHA-256 (RFC 7636 S256)
- Token Assertions: Signed JWT (RFC 7519) & JWKS Key Rotation (RFC 7517)
- Enterprise Privacy: Zero Data Retention (ZDR) Cryptographic Flag
- Delegation: Downstream Scoped Agent Delegation Claims