# archive/2026-05-17-auth-oauth dir: archive/2026-05-17-auth-oauth index: archive/2026-05-17-auth-oauth/.pi-map.index.md ## role Archive directory containing design documents and proposals for an OAuth2/OIDC authentication system with Authentik integration and JWT token management. ## files - .openspec.yaml | Defines an OpenAPI specification file metadata with schema type and creation date - README.md | Documents a project that implements OAuth2/OIDC authentication using Authentik with internal JWTs and database-backed refresh tokens | dep: Authentik, OAuth2, OIDC, JWT - design.md | Design document specifying an OAuth2/OIDC authentication system using Authentik with internal JWT access tokens, DB-backed opaque refresh tokens, and environment-aware cookie policies. | dep: Authentik, Python async SQLAlchemy, Alembic, JWT library, JWKS client, cookie handling library - proposal.md | Proposes a technical implementation plan for adding production-ready OAuth2/OIDC authentication with Authentik integration, JWT session management, and secure token lifecycle handling to a backend API project. | dep: Authentik, OAuth2/OIDC, JWKS, JWT, database, apps/api/src, config, models, auth services, API routes - tasks.md | Task tracking document for implementing OIDC/JWT authentication system with refresh tokens in a backend application. | dep: SQLAlchemy, Alembic, Authentik OIDC, pytest, ruff, mypy, asyncpg, PostgreSQL ## arch Document-driven design specification using markdown-based RFCs, with OpenAPI metadata, separating concerns into design rationale (design.md), implementation planning (proposal.md), task tracking (tasks.md), and project documentation (README.md). ## tags oidc, authentik, oauth2, jwt, authentication, tokens, refresh, design ## symbols - ## workflows - ## dirty -