generated: '2026-08-26' method: probed source: https://authenticate.promptemr.com/.well-known/openid-configuration scope_note: >- Prompt publishes no public API reference, so there is no OpenAPI securitySchemes block to derive from. What IS publicly served, from a host Prompt controls, is the OpenID Connect / RFC 8414 discovery document for the identity provider that fronts the Prompt application. This artifact records that surface verbatim from the probe. It describes how a user or a registered client authenticates to Prompt's platform — it does NOT document a public product API, and no public documentation identifies which resource servers accept these tokens. provider: issuer: https://authenticate.promptemr.com/ host: authenticate.promptemr.com platform: Auth0 tenant on a Prompt-controlled custom domain reached_from: >- https://go.promptemr.com/ (the Prompt application login) redirects with iss=https%3A%2F%2Fauthenticate.promptemr.com%2F schemes: - id: prompt-oidc type: openIdConnect openIdConnectUrl: https://authenticate.promptemr.com/.well-known/openid-configuration in: header header: Authorization format: Bearer endpoints: authorization: https://authenticate.promptemr.com/authorize token: https://authenticate.promptemr.com/oauth/token userinfo: https://authenticate.promptemr.com/userinfo jwks: https://authenticate.promptemr.com/.well-known/jwks.json revocation: https://authenticate.promptemr.com/oauth/revoke device_authorization: https://authenticate.promptemr.com/oauth/device/code dynamic_client_registration: https://authenticate.promptemr.com/oidc/register mfa_challenge: https://authenticate.promptemr.com/mfa/challenge global_token_revocation: https://authenticate.promptemr.com/oauth/global-token-revocation/connection/{connectionName} grant_types: - authorization_code - client_credentials - refresh_token - password - implicit - urn:ietf:params:oauth:grant-type:device_code - urn:ietf:params:oauth:grant-type:token-exchange - urn:ietf:params:oauth:grant-type:jwt-bearer - http://auth0.com/oauth/grant-type/password-realm - http://auth0.com/oauth/grant-type/passwordless/otp - http://auth0.com/oauth/grant-type/mfa-oob - http://auth0.com/oauth/grant-type/mfa-otp - http://auth0.com/oauth/grant-type/mfa-recovery-code response_types: - code - token - id_token - code token - code id_token - token id_token - code token id_token client_authentication: - client_secret_basic - client_secret_post - private_key_jwt - none pkce: supported: true code_challenge_methods: - S256 - plain mfa: supported: true evidence: mfa_challenge_endpoint present in discovery document dpop: supported: true signing_algs: - ES256 token_signing: id_token_algs: - HS256 - RS256 - PS256 token_endpoint_auth_signing_algs: - RS256 - RS384 - PS256 backchannel_logout: supported: true session_supported: true subject_types: - public observations: - >- `client_credentials` is advertised, which means machine-to-machine tokens are issuable against this tenant — the mechanism an integration API would use. No public documentation names the audience/resource server, so this cannot be confirmed as a customer-usable API path. - >- The legacy `password` and `implicit` grants remain enabled on the tenant. Both are discouraged by OAuth 2.1 / RFC 9700 (BCP 240); `password` is disallowed outright. - >- `plain` is still listed alongside `S256` in code_challenge_methods_supported, a weaker PKCE challenge method than S256-only. - >- HS256 is offered as an id_token signing algorithm alongside RS256/PS256. - No security.txt, OAuth protected-resource metadata, or api-catalog is served on any Prompt host. x-evidence: fetched: '2026-08-26' url: https://authenticate.promptemr.com/.well-known/openid-configuration http_status: 200 content_type: application/json bytes: 2669 saved: well-known/prompt-openid-configuration.json