One identity.
Every app you build.
Add “Continue with AXUS ID” to your app. Follow the code, bring your own auth library, or give your AI agent a precise integration brief. Start here, ship with confidence.
Your app. Your starting point.
Fill in your public settings to tailor the configuration.
Register this exact callback URL in the developer console. Use HTTPS in production.
AXUS_ISSUER="https://axusid-website.vercel.app"
AXUS_CLIENT_ID="YOUR_AUID"
AXUS_REDIRECT_URI="http://localhost:3000/api/auth/axus/callback"Sign-in and consent in five steps.
Your app hands off authentication to AXUS ID, then creates its own session when the user returns.
- 01
Register
Save your callback URL and copy your account’s AUID.
- 02
Redirect
Send a fresh PKCE challenge and the required, optional and conditional scopes.
- 03
Review access
The user reviews access. Missing mandatory permissions stop authorization.
- 04
Verify
Exchange the code, verify identity and inspect the approved scope set.
- 05
Sign in
Find or create your local user and start your app’s session.
Two APIs. Two jobs.
Sign-in uses OAuth 2.0 and OpenID Connect. AXUS ID extends authorization with optional and conditional permission lists when your app needs API access. Everything else (users, usernames, variations, passkeys, permissions, tokens) is GraphQL on the engine.
Sign users in · OAuth2 / OIDC
Authorize, token, userinfo, revocation, introspection, discovery. Compliant endpoints your existing stack already understands.
Run AXUS ID functions · GraphQL
The complete engine API behind the login: identities, credentials, delegation, and tokens. Bearer axus_access_token.
Go straight to what you need.
Follow the quickstart
From the first redirect to a verified identity and your own session.
Read the OAuth reference
Compliant endpoints, claims, token lifetimes — the sign-in half.
Inspect a request
See how your settings become a PKCE authorization URL.
Declare permissions
Discover and delegate typed permissions in the right app context.
Become an app
Publish permission templates and connect your dynamic validator.