Native OIDC login (MSC2964, as Element X does) #45

Open
opened 2026-10-05 19:38:05 +00:00 by robocub · 0 comments
Owner

Element X detects a homeserver's OAuth 2.0 metadata (/_matrix/client/v1/auth_metadata; nether.im serves it) and switches to native OIDC login. It shows no password form at all, just "Continue", which opens the browser at the server's login page. Matrix calls this the OAuth 2.0 / next-gen auth API (MSC3861 family: MSC2964 login flow, MSC2965 metadata, MSC2966 dynamic client registration, MSC2967 scopes).

Why bother, when the SSO redirect (#44) already works

  • Servers are moving to OAuth-only; matrix.org already has. Password and legacy SSO login may go away.
  • Proper refresh tokens and per-device session management at the identity provider.
  • Same flow as Element X, so users see one familiar sign-in.

Notes

  • The Matrix Dart SDK we use (commetchat fork, 6.1.1) already ships msc_2964_oidc_login_flow and msc_2966_oidc_dynamic_client_registration.
  • Redirect handling:
    • Linux/Windows: loopback http://localhost:…, allowed for native clients (RFC 8252).
    • Android: a custom scheme or app link.
    • Must work with Tuwunel's /_tuwunel/oidc/registration.
  • Keep the password escape hatch from #44.

Filed with LLM assistance. This is a fork-only issue; never refile it on Commet's tracker.

Element X detects a homeserver's OAuth 2.0 metadata (`/_matrix/client/v1/auth_metadata`; nether.im serves it) and switches to native OIDC login. It shows no password form at all, just "Continue", which opens the browser at the server's login page. Matrix calls this the OAuth 2.0 / next-gen auth API (MSC3861 family: MSC2964 login flow, MSC2965 metadata, MSC2966 dynamic client registration, MSC2967 scopes). ## Why bother, when the SSO redirect (#44) already works - Servers are moving to OAuth-only; matrix.org already has. Password and legacy SSO login may go away. - Proper refresh tokens and per-device session management at the identity provider. - Same flow as Element X, so users see one familiar sign-in. ## Notes - The Matrix Dart SDK we use (commetchat fork, 6.1.1) already ships `msc_2964_oidc_login_flow` and `msc_2966_oidc_dynamic_client_registration`. - Redirect handling: - Linux/Windows: loopback `http://localhost:…`, allowed for native clients (RFC 8252). - Android: a custom scheme or app link. - Must work with Tuwunel's `/_tuwunel/oidc/registration`. - Keep the password escape hatch from #44. --- _Filed with LLM assistance. This is a fork-only issue; never refile it on Commet's tracker._
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
robocub/vommet#45
No description provided.