Skip to content

OAuth 2.0 · OpenID Connect · PHP 8.4

Beffroi

An OpenID Provider for the Symfony ecosystem. On the map of a Symfony application the interface is Symfony, the API is API Platform, and the identity provider is always somewhere else. Beffroi paints that last box the same colour as the other two.

Get started What is Beffroi?

This documentation describes a version that is not released yet

No beffroi/* package is published on Packagist at this point, and the provider is not OpenID Certified yet. Every page here states what the code does today, in the branch this version of the documentation follows. What is not written yet is marked as a stub rather than guessed at.

  • Start here


    What Beffroi is, what it refuses to do, and the shape of the three packages.

    What is Beffroi?

  • Run a provider


    The standalone application, a tenant, a signing key, a first client, a user who signs in.

    Getting started

  • Add it to an application


    The bundle in an existing Symfony application: configuration, routes, persistence, pages.

    The Symfony bundle

  • Read the protocol


    Clients, grants, tokens, discovery, logout, and what each endpoint answers.

    OAuth 2.0 and OpenID Connect

What it is made of

Package What it holds Depends on
beffroi/core Tenants, users, credentials, linked identities, groups, authentication sessions, keys. Pure PHP, no protocol, no HTTP, no Doctrine PHP, PSR interfaces, a handful of libraries
beffroi/oidc OAuth 2.0 and OpenID Connect: clients, authorization requests, grants, tokens, discovery, JWKS, UserInfo, logout. Pure PHP beffroi/core
beffroi/symfony-bundle The Symfony integration: configuration, controllers, security, persistence, login and consent pages both, plus Symfony
beffroi/op The standalone application, on FrankenPHP. The recommended deployment the bundle

What it will not do

Secure by default means there is no option to do it wrong: no implicit flow, no password grant, PKCE with S256 only, redirect URIs compared exactly, iss in every authorization response. Those are properties of the code, not settings of a file.

Secure by default

Where the rest lives

The code is one monorepo, beffroi-php/beffroi, split read-only into one repository per package. This site is written in beffroi-php/docs, one branch per version of the packages it describes.