generated: '2026-09-12' method: probed source: >- https://cms-login.extu.com/.well-known/openid-configuration and https://pexp-login.extu.com/.well-known/openid-configuration note: >- Derived from the two OpenID Connect discovery documents the provider serves, not from an OpenAPI — Affiniti/Extu publishes no API contract. These describe how a HUMAN signs in to the Extu applications (the CMS at app.extu.com and the Partner Experience Platform), not a documented developer authentication flow: there is no public client registration guide, no API key issuance, and no documented audience for a third-party integration. Both tenants are Auth0 custom domains on extu.com hosts (the auth0.com grant-type URNs in grant_types_supported are the tell), so the metadata is Auth0's stock tenant configuration served under Extu's own domain. summary: types: [openIdConnect, oauth2] api_key_in: [] oauth2_flows: [authorizationCode, implicit, clientCredentials, deviceCode, refreshToken, password, tokenExchange, jwtBearer] pkce: [S256, plain] mfa: true dpop: true developer_facing: false schemes: - name: extu-cms-auth0 type: openIdConnect openIdConnectUrl: https://cms-login.extu.com/.well-known/openid-configuration issuer: https://cms-login.extu.com/ authorization_endpoint: https://cms-login.extu.com/authorize token_endpoint: https://cms-login.extu.com/oauth/token userinfo_endpoint: https://cms-login.extu.com/userinfo jwks_uri: https://cms-login.extu.com/.well-known/jwks.json registration_endpoint: https://cms-login.extu.com/oidc/register revocation_endpoint: https://cms-login.extu.com/oauth/revoke device_authorization_endpoint: https://cms-login.extu.com/oauth/device/code backchannel_authentication_endpoint: https://cms-login.extu.com/bc-authorize token_endpoint_auth_methods: [client_secret_basic, client_secret_post, private_key_jwt, none] id_token_signing_alg_values: [HS256, RS256, PS256] dpop_signing_alg_values: [ES256] scope_count: 14 serves: Extu CMS application at https://app.extu.com sources: [well-known/affiniti-cms-login-openid-configuration.json] - name: extu-pexp-auth0 type: openIdConnect openIdConnectUrl: https://pexp-login.extu.com/.well-known/openid-configuration issuer: https://pexp-login.extu.com/ authorization_endpoint: https://pexp-login.extu.com/authorize token_endpoint: https://pexp-login.extu.com/oauth/token userinfo_endpoint: https://pexp-login.extu.com/userinfo jwks_uri: https://pexp-login.extu.com/.well-known/jwks.json registration_endpoint: https://pexp-login.extu.com/oidc/register revocation_endpoint: https://pexp-login.extu.com/oauth/revoke device_authorization_endpoint: https://pexp-login.extu.com/oauth/device/code backchannel_authentication_endpoint: https://pexp-login.extu.com/bc-authorize end_session_endpoint: https://pexp-login.extu.com/oidc/logout token_endpoint_auth_methods: [client_secret_basic, client_secret_post, private_key_jwt, none] id_token_signing_alg_values: [HS256, RS256, PS256] dpop_signing_alg_values: [ES256] scope_count: 14 serves: Extu Partner Experience Platform (PEXP) sources: [well-known/affiniti-pexp-login-openid-configuration.json]