erlef/oidcc
64.6
Adequate · 2 October 2026
9.6k
lines of production code
Erlang
with Elixir
2
measurements over time
What this system is
This system is an OpenID Connect client library for the BEAM platform, providing core functionality for authentication flows such as authorization, token management, and logout. It offers a high-level Elixir API and GenServer-based workers for handling provider configurations and JSON Web Keys, while supporting advanced security features like FAPI 2.0, JARM, and DPoP. The library is designed to be extensible through pluggable HTTP adapters and includes comprehensive tooling for code generation and certification testing.
Features
Add branded SVG assets and license files
Added SVG logo assets for the project (logo.svg), the OpenID Foundation certification mark (certified-light.svg, certified-dark.svg), and the Erlang Ecosystem Foundation logo (erlef-logo-light.svg, erlef-logo-dark.svg), along with corresponding SPDX license files to ensure REUSE compliance.
assets · high confidence
Introduce Elixir wrapper modules for core OIDC operations
The library adds a set of new Elixir modules (\Oidcc.Authorization\, \Oidcc.ClientContext\, \Oidcc.ClientRegistration\, \Oidcc.Logout\, \Oidcc.ProviderConfiguration\, \Oidcc.Token\, \Oidcc.TokenIntrospection\, and \Oidcc.Userinfo\) that wrap the underlying Erlang \oidcc\ functions. These modules provide idiomatic Elixir structs for client contexts, tokens, and provider configurations, and expose telemetry events for key lifecycle stages such as authorization redirects, token retrieval, and logout initiation.
lib/oidcc · high confidence
Introduction of high-level Oidcc wrapper module
A new \Oidcc\ module has been added to provide a high-level interface for OpenID Connect operations. This module exposes convenience functions for creating authorization redirect URLs, retrieving tokens via authorization codes, refreshing tokens, and introspecting access tokens. It acts as a facade over the underlying \:oidcc\ library, handling token normalization and providing a unified API for client authentication and token management.
lib · high confidence
New Erlang record definitions for OIDC provider configuration, client context, and token structures
The library introduces a set of new Erlang header files in the include directory to define the core data structures for OpenID Connect operations. These include \oidcc\_provider\_configuration.hrl\ for mapping provider metadata (such as endpoints, supported algorithms, and capabilities like JARM, DPoP, and PAR), \oidcc\_client\_registration.hrl\ for client metadata and registration responses, \oidcc\_client\_context.hrl\ for managing client state and keys, and \oidcc\_token.hrl\ along with \oidcc\_token\_introspection.hrl\ for representing access, ID, and refresh tokens as well as introspection results. A master header \oidcc.hrl\ is also added to aggregate these includes, providing a unified entry point for developers using the library.
include · high confidence
New Provider Configuration Worker API
A new \Oidcc.ProviderConfiguration.Worker\ module has been added to provide a GenServer-based interface for loading and continuously refreshing OIDC provider configuration and JWKs. Users can now start the worker via \start\_link/1\ with an issuer and optional configuration options, and retrieve the current configuration or JWKs using \get\_provider\_configuration/1\ and \get\_jwks/1\. The worker also supports manual refresh operations via \refresh\_configuration/1\, \refresh\_jwks/1\, and \refresh\_jwks\_for\_unknown\_kid/2\ to handle key rotation or unknown key IDs.
_lib/oidcc/provider\configuration · high confidence
New mix task to generate OpenID Connect provider configuration workers
A new Mix task, \oidcc.gen.provider\_configuration\_worker\, is now available to scaffold an OpenID Connect provider configuration worker. When invoked with options like \--name\ and \--issuer\, it automatically adds the worker to the application's supervision tree and configures the issuer in \runtime.exs\, supporting both static values and environment variables. If the \igniter\ dependency is not installed, the task provides a clear error message directing users to install it.
lib/mix · high confidence
OIDCC library v3.9.0 initial release
The OpenID Connect client library for the BEAM is released as version 3.9.0. This release introduces a pluggable HTTP adapter architecture, allowing users to swap the default \httpc\ transport for custom implementations via the \http\_adapter\ request option. It also adds support for OpenID Connect Dynamic Client Registration, JARM (JWT Secured Authorization Response Mode), and DPoP (Demonstrating Proof of Possession). The library now uses OTP's built-in JSON module instead of \jose\/\jsx\ for decoding, and requires OTP 27 and Elixir 1.17.
src · high confidence
Behavioural changes
OIDC certification testing now uses OIDCerto-based plug implementation
The certification suite has been updated to use an OIDCerto-based implementation via the \oidcc\_plug\ library, replacing the previous approach. This change introduces a new \config.json\ defining specific test plans (such as Basic, Comprehensive, and RP Initiated Logout) and an \implementation\_plug.exs\ script that manages the conformance test server lifecycle, including client registration and server startup. The implementation allows overriding the \oidcc\_plug\ version via the \OIDCC\_PLUG\_VERSION\ environment variable to test against unreleased branches or specific Hex versions.
certification · high confidence
Project refactored for Erlang Ecosystem Foundation with OTP 27 requirement and Apache 2.0 licensing
The project has been refactored and transferred to the Erlang Ecosystem Foundation, introducing a minimum requirement of Erlang/OTP 27 (as specified in rebar.config and .tool-versions). The license has been updated to Apache 2.0, and the repository now includes comprehensive tooling configurations such as Credo (.credo.exs), Erlang/Elixir formatters (.formatter.exs), and Elvis (elvis.config). Additionally, the README has been expanded to document supported OpenID Connect features (including FAPI 2.0, JARM, and DPoP) and display certification and security audit badges.
(repo-wide) · high confidence
Structured token types for access, ID, and refresh tokens
The library now exposes dedicated structs for access, ID, and refresh tokens (\Oidcc.Token.Access\, \Oidcc.Token.Id\, \Oidcc.Token.Refresh\), replacing the previous opaque record-based approach. This change provides a clearer API surface, with \Oidcc.Token.Access\ including a new \authorization\_headers/4\ function (available since 3.2.0) to simplify generating authorization headers for API calls.
lib/oidcc/token · high confidence
Test coverage
Added comprehensive test suite for OIDC core flows; Added test fixtures for OpenID Connect and FAPI2 profiles; Added tests for the OIDCC provider configuration worker generator; Expanded test coverage for OIDC client operations and configuration.
Dependencies
Update project dependencies and lockfile
The mix.exs manifest and mix.lock file have been updated to refresh the project's dependency tree. Key updates include raising the minimum Elixir requirement to version 1.17, updating the Igniter optional dependency to support versions up to 0.9.0 (with the lockfile resolving to 0.8.3), and bumping ExDoc to 0.40.3. Other dependencies such as telemetry, jose, and credo have also been updated to their latest compatible versions.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 63 → 65 (+1.7)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 97 → 97 (+0.0)
- Architecture 100 → 100 (+0.0)
- Maturity 38 → 42 (+3.7)
- Readiness 73 → 72 (-0.3)
- Security 97 → 98 (+0.5)
Resolved (6)
- Coverage not measured — no coverage collector is wired up
- Hotspot: src/oidcc_authorization.erl (src/oidcc_authorization.erl)
- Hotspot: src/oidcc_jwt_util.erl (src/oidcc_jwt_util.erl)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/oidcc.erl)
- Off-boarding risk: anonymized user #1
New (3)
- Medium CVE: EEF-[CVE redacted] (mix.lock)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/oidcc.erl)
- Off-boarding risk: anonymized user #1
Changes since last survey
- 2 commits — 2 feature/other, 0 fixes
By area
- .github/workflows — 2 commits
Notable commits
- change: Bump the github-actions group with 3 updates (#551)
- change: Bump the github-actions group with 4 updates (#549)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
erlef/oidcc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4914d8d0bad2aa9c3dba51662808171bba94fb6f — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.