---
title: "Oauth Authorization Server Metadata"
method: GET
path: "/.well-known/oauth-authorization-server"
tags: ["auth-keycloak"]
---

# Oauth Authorization Server Metadata

`GET /.well-known/oauth-authorization-server`

RFC 8414 OAuth 2.0 Authorization Server Metadata.

Root-level sibling of the realm OIDC discovery doc, advertising the
authorization-code + PKCE surface. `jwks_uri` is deliberately OMITTED — we
sign with HS256 (symmetric), there is no public key to publish, and RFC 8414
does not require it. Host-correct via `discovery_issuer(request.base_url)`.

## Response `200`

Successful Response

- unknown

## Other responses

- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Validation Error
- `500` — Internal Server Error

---

[API](https://skmtc.dev/geopera/apis/geopera-data-platform.md) · [All operations](https://skmtc.dev/geopera/apis/geopera-data-platform/llms.txt) · [OpenAPI document](https://skmtc.dev/geopera/apis/geopera-data-platform/revisions/4e207e5020c5?raw)
