Authentication and capabilities
Understand OIDC authentication, backend authorization, browser sessions, and MCP permissions.
SmartGare separates identity from authorization.
Authentication
The backend is a stateless OAuth2 resource server. It validates the JWT issuer, signature, and expiry and creates no application session.
A station may integrate an existing OIDC provider. SmartGare also ships an optional Keycloak realm with password login, WebAuthn passkeys, and TOTP setup. It starts only when selected and ships no users or credentials.
Authorization
Permissions use stable capability names:
referential.carrier:read
referential.carrier:write
referential.vehicle:import-permits
referential.vehicle:trigger-expiry-watch
siv.display-point:write
rules.rule:readHTTP handlers and MCP tools declare the permission they require. Architecture tests fail when a new operation is unguarded.
Frontend sessions
The back-office uses a server-managed OIDC session. Bearer and refresh tokens remain in HTTP-only cookies and server-side code. Supervision and counter use the shared browser OIDC adapter.
Capability bootstrap responses let applications hide or disable unavailable controls. They never replace backend enforcement.
Public paths
Actuator health/info and API documentation are public by configuration. Every other path requires authentication unless explicitly allowlisted.
Never expose a credential
Do not place access tokens, refresh tokens, client secrets, connection strings, or signed URLs in browser code, documentation, screenshots, logs, or examples.