Beyond Identity signs users in with a passkey bound to the user's device. Authdog talks to the OIDC endpoints on the application you create in a Beyond Identity realm.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Beyond Identity**, and click **Enable**. Copy the redirect URI shown in the form:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the application

1. In the Beyond Identity console, open the tenant, realm, and create an application that uses the External Protocol (OIDC).
2. Set the redirect URI to the value copied from Authdog.
3. Request the scopes `openid`, `profile`, and `email`.
4. Copy the **Client ID** and **Client secret**.
5. Copy the application base URL. It looks like `https://auth-us.beyondidentity.com/v1/tenants/{tenant}/realms/{realm}/applications/{app}` and has no trailing slash. That base is the Domain URI.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The client identifier from the Beyond Identity application |
| **Client Secret** | The client secret from the Beyond Identity application |
| **Domain URI** | The application base URL, with `/authorize` removed |

Save, then toggle the connection **active**.

## What Beyond Identity returns

Authdog requests the `openid profile email` scopes and reads the profile from `<application base>/userinfo`.

The userinfo endpoint returns `sub`, name, and email claims for the authenticated user.

Paste the application base as the Domain URI. Do not include `/authorize`, `/token`, or `/userinfo`.

## Test it

1. Open your environment's hosted sign-in page, or link to `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Beyond Identity button and complete the flow.
3. Confirm the user appears under **Users** in the console with a Beyond Identity identity linked.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | Client ID or secret from a different application |
| Redirect or callback URL error | The URI registered with Beyond Identity does not match Authdog's exactly |
| 404 on authorize | The Domain URI includes `/authorize` or points at an older fixed host |
| Works in one environment only | Each environment has its own `connectionId`, and so its own redirect URI to register |

## Related

| Read | To learn how to |
| --- | --- |
| [Connectors](/docs/connectors) | Set up any other social provider |
