Thunder Authentication

How end-user identity works on the platform — Thunder, the IDP wired into the API gateway, signs users in and components authorize them. Covers the auth platform-resource dependency, the platform-owned OAuth client, the window._env_.<DEP>_* runtime keys, OIDC + PKCE in the SPA, and resolving the caller's role and directory record on the backend. Apply to any SPA whose users sign in, and to every protected backend they call.

wso2 e1ed134 15.1 KB Updated

File contents

wso2/labs-agentic-engineer/tree/main/skills/thunder-authentication commit e1ed134872

Frequently asked questions

npx skillmds@latest add wso2/thunder-authentication