SSO Server (sso.gerege.mn)

OpenID Connect 1.0 provider — e-ID Mongolia смарт картаар баталгаажуулна.

Нээлттэй — бүх 3-р талын platform-д

sso.gerege.mn нь аливаа систем, platform, апп-д нээлттэй.

developer.gerege.mn дээр app бүртгүүлж client_id авахад хангалттай.

OIDC Endpoints

EndpointURL
Discovery/.well-known/openid-configuration
Authorization/oauth/authorize
Token/oauth/token
UserInfo/oauth/userinfo
JWKS/.well-known/jwks.json
Introspect/oauth/introspect
Revoke/oauth/revoke

Дэмждэг scopes

ScopeТайлбар
openidЗаавал — sub, iss, aud
profilename, given_name, family_name, cert_serial
posPOS Plugin API — tenant_id, tenant_role, plan
socialSocial Commerce API
paymentPayment API

ID Token Claims

{

"sub": "eid-12345678",

"name": "БАТБОЛД Ганбаатар",

"given_name": "Ганбаатар",

"family_name": "БАТБОЛД",

"cert_serial": "ABC123DEF456",

"identity_assurance_level": "high",

"amr": ["eid"],

"tenant_id": "t_abc123",

"tenant_role": "owner",

"plan": "pro"

}

Тохиргоо (Environment)

VariableТайлбар
SSO_ISSUERIssuer URL (https://sso.gerege.mn)
SSO_PRIVATE_KEY_PATHEC private key path
DATABASE_URLPostgreSQL connection string
REDIS_URLRedis connection string
EID_BASE_URLe-ID Mongolia API URL