{"service":"towly-openid2","version":"0.1.0-o6","op_endpoint":"https://openid2.towly.ai/provider","xrds_url":"https://openid2.towly.ai/xrds","issuer":"https://api.towly.ai","association":"stateless (HKDF-SHA256 per-handle keys); DH session types refused; dumb mode supported","attribute_sources":["email","name","nickname","given_name","family_name"],"identity_model":"directed identity: pairwise per (user, RP realm)","honest_limits":["OpenID 2.0 is deprecated. This shim exists only so legacy relying parties keep working; new integrations must use OIDC.","Associations are stateless: per-handle HMAC keys are derived with HKDF-SHA256 from the server secret, so no association store exists and any replica verifies any signature. DH-SHA1/DH-SHA256 association session types are refused; use session_type=no-encryption over TLS, or dumb mode (fresh per-response handle verified via check_authentication).","Attribute Exchange and Simple Registration release only the claims Towly actually issues: email, full name, nickname, and given/family name (best-effort split of the full name). Any other requested attribute is silently omitted.","Directed identity only. The claimed identifier is pairwise per user and RP realm and stable for that pair. RP-supplied identifiers other than identifier_select are rejected unless they exactly match the pairwise identifier for the authenticated user and realm.","checkid_immediate succeeds without user interaction only when the user already holds a shim session (from a recent interactive login) or a silent OIDC grant (prompt=none) succeeds; otherwise the RP receives setup_needed.","No public legacy-RP conformance suite exists for OpenID 2.0. Verification is performed with a purpose-built test RP harness (shipped in test/rp-harness.js) that exercises discovery, association, checkid_setup, positive assertion, direct signature verification, and check_authentication."]}