Badge replaces stored credentials with a device-independent key derived at each authentication, so there is no secret at rest to steal. It suits products where credential-database exposure is the threat you are designing against.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Badge**, and click **Enable**. Copy the redirect URI shown in the form:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the application

1. Create an OIDC application in your Badge tenant.
2. Add the redirect URI from Authdog to the application.
3. Copy the **Client ID** and **Client Secret**.
4. Note the tenant host to use as the Domain URI.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The client identifier from the provider |
| **Client Secret** | The client secret from the provider |
| **Domain URI** | Your Badge tenant host |

Save, then toggle the connection **active**.

> **Caution**
>
> Authdog substitutes the Domain URI into this provider's endpoints for
> AWS Cognito, Salesforce Community, Shopify, Klarna, and Keycloak. This
> connector accepts the field in the console but is not covered by that
> substitution on both legs of the flow, so verify it end to end in a
> development environment before you rely on it in production.

## What Badge returns

Authdog requests the `openid profile email` scopes and reads the profile from ``https://<domain>/userinfo``.

The tenant's userinfo endpoint returns the standard OpenID Connect identity claims.

## Test it

1. Open your environment's hosted sign-in page, or link to `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Badge button and complete the flow.
3. Confirm the user appears under **Users** in the console with a Badge identity linked.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | Credentials issued by a different tenant |
| Redirect or callback URL error | The URI registered with the provider does not match Authdog's exactly |
| Works in one environment only | Each environment has its own `connectionId`, and so its own redirect URI to register |

## Related

| Read | To learn how to |
| --- | --- |
| [Connectors](/docs/connectors) | Set up any other social provider |
