Authentication flows
Understand supported OAuth 2.0 and OpenID Connect sign-in patterns.
Available in sandboxProduction approval required
Standards
OAuth 2.0 + OpenID Connect
Security
Authorization Code + PKCE
Healthcare identity
France + Luxembourg
Access
Sandbox public · production approved
Overview
Mediloop Identity provides a standards-based boundary for authentication and authorization. Public developers can build and test in sandbox; production access is controlled.
Server-side applications
OIDC scopes
openid profile email
# Additional healthcare or organization claims require explicit approval.Security notes
Use least-privilege scopes, exact redirect URI matching, PKCE for public clients, short-lived access tokens and secure server-side storage for confidential credentials. Do not infer authorization from identity claims alone.
Errors
| Error | Meaning |
|---|---|
| invalid_request | Malformed or incomplete protocol request |
| invalid_client | Client authentication or registration failed |
| invalid_grant | Authorization grant is invalid or expired |
| access_denied | User, policy or approval denied access |