Library for working with OpenID Connect and implementing clients.

It currently supports these features:

  • discover OpenID Provider metadata
  • parsing and validating id tokens
  • basic tools for implementing implicit and authorization code flow
  • authentication for command line tools

Besides authentication providers that support OpenID Connect, this library can also work with other authentication providers supporting oauth2, like Facebook. For these providers, some features (e.g. discovery and id tokens) will not work. You should define the metadata for those providers manually, except for Facebook, which is predefined in the library.


A simple usage example:

import 'package:openid_client/openid_client.dart';

main() async {

  // print a list of known issuers

  // discover the metadata of the google OP
  var issuer = await;
  // create a client
  var client = new Client(issuer, "client_id", "client_secret");
  // create a credential object from authorization code
  var c = client.createCredential(code: "some received authorization code");

  // or from an access token
  c = client.createCredential(accessToken: "some received access token");

  // or from an id token
  c = client.createCredential(idToken: "some id token");      

  // get userinfo
  var info = await c.getUserInfo();
  // get claims from id token if present
  // create an implicit authentication flow
  var f = new Flow.implicit(client);
  // or an explicit flow
  f = new Flow.authorizationCode(client);
  // set the redirect uri
  f.redirectUri = Uri.parse("http://localhost");
  // do something with the authentication url
  // handle the result and get a credential object
  c = await f.callback({
    "code": "some code",
  // validate an id token
  var violations = await c.validateToken();

Command line tool


pub global activate openid_client


Show a list of known OpenID providers:

openid_client issuers-list

Discover and show the metadata of an OP:

openid_client issusers-discover

Show a list of known clients:

openid_client clients-list

Add a client:

openid_client clients-add --secret optional_secret client_id

Remove a client:

openid_client clients-remove client_id

Authenticate with a client:

openid_client clients-auth --secret optional_secret client_id

Show the content of an id token and validate it:

openid_client tokens-validate eyJhbGciOiJSUzI1NiIsImtpZCI6ImE2YzJjNmQ0ZTZkYTFmOWJjMTdmYzhkMzExMzNiOTJmMDdlOTgxMTkifQ.eyJpc3MiOiJodHRwczovL2FjY291bnRzLmdvb2dsZS5jb20iLCJpYXQiOjE0ODU4ODQyNzcsImV4cCI6MTQ4NTg4Nzg3NywiYXRfaGFzaCI6Ik9nWUlZRzM1WXB6RmVvRlZBeWd1VUEiLCJhdWQiOiI1ODExNTUxMDQ5NDMtcnBqazBzanZucDFrZ2FkYzV0Mm5pOXFvYWt0ZGpzMjEuYXBwcy5nb29nbGV1c2VyY29udGVudC5jb20iLCJzdWIiOiIxMTI2NzgyNTk2NzYyMTE3MDcxNDgiLCJlbWFpbF92ZXJpZmllZCI6dHJ1ZSwiYXpwIjoiNTgxMTU1MTA0OTQzLXJwamswc2p2bnAxa2dhZGM1dDJuaTlxb2FrdGRqczIxLmFwcHMuZ29vZ2xldXNlcmNvbnRlbnQuY29tIiwiZW1haWwiOiJyaWsuYmVsbGVuc0BnbWFpbC5jb20iLCJuYW1lIjoiUmlrIEJlbGxlbnMiLCJwaWN0dXJlIjoiaHR0cHM6Ly9saDUuZ29vZ2xldXNlcmNvbnRlbnQuY29tLy1lRmpwUXFfUTZWUS9BQUFBQUFBQUFBSS9BQUFBQUFBQUFCUS9md1U0alVicTJ5US9zOTYtYy9waG90by5qcGciLCJnaXZlbl9uYW1lIjoiUmlrIiwiZmFtaWx5X25hbWUiOiJCZWxsZW5zIiwibG9jYWxlIjoibmwifQ.TlXzuNLdd5hX-bzMrwBaclcE8z4So2wFJAZ_H7hGz8YA4lCxHV8iON8yuJ1PdXGuOOkDXScj4qSPK80IZ_J29Uf2azCH83djpjyP4McB_dG4zXkUSFGFTHiNnqmvFbMmL-91A74teAr1ZHDx5-so2bHs16_c8immj2YM5GqlN4FG_IFCqRZ-7jEn9m_SjBXpb_NahiDB-bk47npmM9GIWq4OhV4e4tpFO1XY7H4fDHoiBhkc1nrbUjiqTH3VOJVQNp6FjiO2ErR7UWWnSKX6PMFDJ-U-QSsC8gu0PtuIa1ZUXvTAdX5vKt_fsKijbiT0xUUq8xJATaDh8-aBsNKpqQ

  • Initial version


// Copyright (c) 2017, rbellens. All rights reserved. Use of this source code
// is governed by a BSD-style license that can be found in the LICENSE file.

import 'package:openid_client/openid_client.dart';
import 'package:openid_client/src/html.dart';
import 'dart:html' hide Client, Credential;
import 'dart:convert';
import 'package:angular2/platform/browser.dart';
import 'package:angular2/core.dart';

main() async {


  var issuer = await''));
  var client = new Client(issuer,

  var a = await new Authenticator(client);

  var c = await a.credential;

  if (c==null) {
      ..disabled = false

  } else {
    var info = await c.getUserInfo();
    document.querySelector("#name").text =;
    document.querySelector("#picture").src = info.picture.toString();



@Component(selector: 'my-app', templateUrl: 'app_component.html')
class AppComponent {
  List<Uri> issuers = Issuer.knownIssuers.toList();

  Issuer selectedIssuer;

  Map<String,List<String>> allClients = {};

  List<String> clients = [];

  Client selectedClient;

  Authenticator authenticator;

  Credential credential;

  UserInfo userinfo;

  AppComponent() {
    allClients = JSON.decode(window.localStorage["openid_clients"] ?? "{}");

    () async {
      if (window.localStorage.containsKey("issuer")) {
        await select(window.localStorage["issuer"]);
        if (selectedIssuer!=null) {
          if (window.localStorage.containsKey("client_id")) {
    print("clients $allClients");

  select(v) async {
    print("select $v");
    window.localStorage["issuer"] = v;
    this.selectedClient = null;
    this.clients = [];
    this.selectedIssuer = await;
    this.clients = allClients[selectedIssuer.metadata.issuer.toString()] ??= [];

  selectClient(String v) async {
    print("select client $v");
    if (!clients.contains(v)) {
      window.localStorage["openid_clients"] = JSON.encode(allClients);
    window.localStorage["client_id"] = v;
    selectedClient = new Client(selectedIssuer, v);
    authenticator = new Authenticator(selectedClient);
    credential = null;
    userinfo = null;
    credential = await authenticator.credential;
    print("select client $credential");
    userinfo = await credential.getUserInfo();
    print("userinfo $userinfo");

  login() {

  logout() {
    userinfo = null;

