openapi: 3.2.0 info: title: QUT ESOE OpenID Connect Provider Identity API version: 1.0.0 summary: Queensland University of Technology's institution-operated OpenID Connect / OAuth 2.0 authorization server. description: Machine-readable contract for the OAuth 2.0 / OpenID Connect authorization server that Queensland University of Technology operates at esoe.qut.edu.au. contact: name: Queensland University of Technology url: https://www.qut.edu.au/ license: name: Not stated identifier: NOASSERTION x-operator: institution x-operator-basis: DNS + APNIC whois + TLS subject. esoe.qut.edu.au -> 131.181.118.129 (no CNAME); netname QUT-AU, org ORG-QUOT1-AP "Queensland University of Technology", origin AS7575; certificate subject O=QUEENSLAND UNIVERSITY OF TECHNOLOGY, CN=esoe.qut.edu.au, issuer DigiCert Global G2 TLS RSA SHA256 2020 CA1. x-generated: '2026-09-01' x-method: derived x-source: https://esoe.qut.edu.au/auth/realms/qut/.well-known/openid-configuration servers: - url: https://esoe.qut.edu.au/auth/realms/qut description: QUT ESOE Keycloak realm `qut` (production, live 2026-09-01) security: - oauth2: [] tags: - name: Identity description: End-user claims and session termination. paths: /protocol/openid-connect/userinfo: get: tags: - Identity operationId: getUserInfo summary: OpenID Connect UserInfo description: Returns claims about the authenticated end user. Claims advertised by this realm are aud, sub, iss, auth_time, name, given_name, family_name, preferred_username, email and acr. security: - bearerAuth: [] responses: '200': description: Claims for the subject of the presented access token. content: application/json: schema: $ref: '#/components/schemas/UserInfo' '401': description: Missing, expired or insufficiently scoped access token. content: application/json: schema: $ref: '#/components/schemas/OAuthError' /protocol/openid-connect/logout: get: tags: - Identity operationId: endSession summary: RP-initiated logout security: [] responses: '302': description: Session terminated and the user agent redirected. components: schemas: OAuthError: type: object required: - error properties: error: type: string examples: - invalid_request - invalid_client - invalid_grant - unauthorized_client - unsupported_grant_type - invalid_scope - access_denied - server_error error_description: type: string error_uri: type: string format: uri UserInfo: type: object required: - sub properties: sub: type: string iss: type: string format: uri aud: type: string auth_time: type: integer name: type: string given_name: type: string family_name: type: string preferred_username: type: string email: type: string format: email acr: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: Access token issued by this realm. oauth2: type: oauth2 description: Scopes below are exactly the `scopes_supported` array of the live discovery document. `Service_Account`, `service_account` and `Integsvc_test_client` are QUT-specific client scopes, not standard OpenID Connect scopes. flows: authorizationCode: authorizationUrl: https://esoe.qut.edu.au/auth/realms/qut/protocol/openid-connect/auth tokenUrl: https://esoe.qut.edu.au/auth/realms/qut/protocol/openid-connect/token refreshUrl: https://esoe.qut.edu.au/auth/realms/qut/protocol/openid-connect/token scopes: openid: Authenticate the end user and issue an ID token. profile: Basic profile claims. email: Email address claim. phone: Phone number claim. address: Address claim. offline_access: Issue a refresh token usable while the user is offline. roles: Realm and client role claims. basic: Baseline claim set. acr: Authentication context class reference claim. web-origins: Allowed web origins for CORS. microprofile-jwt: MicroProfile JWT claim mapping. Service_Account: QUT-specific service account scope. service_account: QUT-specific service account scope. Integsvc_test_client: QUT-specific integration service test client scope. clientCredentials: tokenUrl: https://esoe.qut.edu.au/auth/realms/qut/protocol/openid-connect/token scopes: Service_Account: QUT-specific service account scope. service_account: QUT-specific service account scope.