Skip to content

Zitadel IAM, OIDC & OAuth 2.0 PKCE Integration ​

1. Single Sign-On Authentication Architecture ​

ScholarGate Identity implements OpenID Connect (OIDC 1.0) and OAuth 2.0 Proof Key for Code Exchange (PKCE) to deliver Single Sign-On across institutional applications.

mermaid
sequenceDiagram
    autonumber
    actor User as Student / Teacher
    participant App as Client Application (CBT / E-Rapor)
    participant Portal as ScholarGate Identity Portal
    participant Zitadel as Zitadel IAM Authority

    User->>App: Click "Login with ScholarGate SSO"
    App->>Portal: Redirect to OIDC authorize endpoint
    Portal->>Zitadel: Initiate OIDC Auth Code Flow + PKCE Challenge
    Zitadel->>User: Display Single Door Authentication UI

    User->>Zitadel: Input Credentials / Authenticate via Google
    Zitadel-->>Portal: Authorization Code Callback
    Portal->>Zitadel: Exchange Code + PKCE Verifier for Id Token & Access Token
    Zitadel-->>Portal: Return Signed ID Token (JWT)

    Portal->>Portal: Resolve Identity (NIK / NIP / NISN Lookup)
    Portal-->>App: Issue Authenticated Session & User Metadata

2. Identity Resolution Engine ​

During user login, ScholarGate Identity automatically resolves user roles and administrative attributes:

  • Teachers & Staff (PTK): Dual resolution matching Civil Servant NIP (NIP) or Non-PNS Identity Number (NIK).
  • Students: Resolution based on National Student Number (NISN) or local Student ID (NIK).
  • Single Logout (SLO): Terminating a session on ScholarGate Identity dispatches OIDC SLO backchannel notifications to invalidate sessions across all client applications.