Appearance
Zitadel IAM, OIDC & OAuth 2.0 PKCE Integration
1. Single Sign-On Authentication Architecture
ScholarGate Identity implements OpenID Connect (OIDC 1.0) and OAuth 2.0 Proof Key for Code Exchange (PKCE) to deliver Single Sign-On across institutional applications.
mermaid
sequenceDiagram
autonumber
actor User as Student / Teacher
participant App as Client Application (CBT / E-Rapor)
participant Portal as ScholarGate Identity Portal
participant Zitadel as Zitadel IAM Authority
User->>App: Click "Login with ScholarGate SSO"
App->>Portal: Redirect to OIDC authorize endpoint
Portal->>Zitadel: Initiate OIDC Auth Code Flow + PKCE Challenge
Zitadel->>User: Display Single Door Authentication UI
User->>Zitadel: Input Credentials / Authenticate via Google
Zitadel-->>Portal: Authorization Code Callback
Portal->>Zitadel: Exchange Code + PKCE Verifier for Id Token & Access Token
Zitadel-->>Portal: Return Signed ID Token (JWT)
Portal->>Portal: Resolve Identity (NIK / NIP / NISN Lookup)
Portal-->>App: Issue Authenticated Session & User Metadata2. Identity Resolution Engine
During user login, ScholarGate Identity automatically resolves user roles and administrative attributes:
- Teachers & Staff (PTK): Dual resolution matching Civil Servant NIP (
NIP) or Non-PNS Identity Number (NIK). - Students: Resolution based on National Student Number (
NISN) or local Student ID (NIK). - Single Logout (SLO): Terminating a session on ScholarGate Identity dispatches OIDC SLO backchannel notifications to invalidate sessions across all client applications.