generated: '2026-07-18' method: searched source: https://secure.blueleaf.com/.well-known/openid-configuration docs: https://www.blueleaf.com/developer/ summary: types: [oauth2, openIdConnect] oauth2_flows: [authorizationCode] pkce: [S256, plain] token_endpoint_auth_methods: [client_secret_basic, client_secret_post] schemes: - name: OpenIDConnect type: openIdConnect openIdConnectUrl: https://secure.blueleaf.com/.well-known/openid-configuration issuer: https://secure.blueleaf.com sources: [well-known/blueleaf-openid-configuration.json] - name: OAuth2 type: oauth2 flows: - flow: authorizationCode authorizationUrl: https://secure.blueleaf.com/oauth/authorize tokenUrl: https://secure.blueleaf.com/oauth/token refreshUrl: https://secure.blueleaf.com/oauth/token scopes: [openid, email, profile] endpoints: userinfo: https://secure.blueleaf.com/oauth/userinfo introspection: https://secure.blueleaf.com/oauth/introspect revocation: https://secure.blueleaf.com/oauth/revoke jwks_uri: https://secure.blueleaf.com/.well-known/jwks.json id_token_signing_alg: [RS256] sources: [well-known/blueleaf-openid-configuration.json] notes: >- Blueleaf operates an OAuth 2.0 / OpenID Connect provider at secure.blueleaf.com (authorization_code grant with refresh tokens, PKCE S256). Additional data-access API details (account balances, holdings, transactions) are gated behind sales contact and not publicly documented.