Beyond Identity signs users in with a passkey bound to the user's device. Authdog talks to the OIDC endpoints on the application you create in a Beyond Identity realm.
Copy the redirect URI
In the Authdog console, select the project and environment, open Authentication > Providers, find Beyond Identity, and click Enable. Copy the redirect URI shown in the form:
https://identity.authdog.com/api/v1/callback/<connectionId>Create the application
- In the Beyond Identity console, open the tenant, realm, and create an application that uses the External Protocol (OIDC).
- Set the redirect URI to the value copied from Authdog.
- Request the scopes
openid,profile, andemail. - Copy the Client ID and Client secret.
- Copy the application base URL. It looks like
https://auth-us.beyondidentity.com/v1/tenants/{tenant}/realms/{realm}/applications/{app}and has no trailing slash. That base is the Domain URI.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | The client identifier from the Beyond Identity application |
| Client Secret | The client secret from the Beyond Identity application |
| Domain URI | The application base URL, with /authorize removed |
Save, then toggle the connection active.
What Beyond Identity returns
Authdog requests the openid profile email scopes and reads the profile from <application base>/userinfo.
The userinfo endpoint returns sub, name, and email claims for the authenticated user.
Paste the application base as the Domain URI. Do not include /authorize, /token, or /userinfo.
Test it
- Open your environment's hosted sign-in page, or link to
https://identity.authdog.com/api/v1/signin/<connectionId>. - Select the Beyond Identity button and complete the flow.
- Confirm the user appears under Users in the console with a Beyond Identity identity linked.
Troubleshooting
| Symptom | Cause |
|---|---|
invalid_client |
Client ID or secret from a different application |
| Redirect or callback URL error | The URI registered with Beyond Identity does not match Authdog's exactly |
| 404 on authorize | The Domain URI includes /authorize or points at an older fixed host |
| Works in one environment only | Each environment has its own connectionId, and so its own redirect URI to register |
Related
| Read | To learn how to |
|---|---|
| Connectors | Set up any other social provider |