Live trust report · Signet
Status is being refreshed.
The last snapshot is visible while Signet completes one bounded refresh. Machine health fails closed if it cannot finish.
Live checks
Runtime
Read-only dependency checks shared with the machine health endpoint.
Web service
Public HTTP routes are accepting requests
Current requestDatabase
Persistent storage accepted a context-bounded connection check
Live probeIdentity cache
Provides identity lookups used by authenticated request paths
Live probeAdministration cache
Speeds up administrative status counts; failures do not block core flows
Live probeClient cache
Accelerates OAuth client lookups with a database fallback
Live probeToken signing engine
A non-persistent token was signed and verified in memory
In-memory self-testToken cache
Accelerates online token verification with a database fallback
Live probeRate-limit store
Stores distributed rate-limit counters when Redis mode is active
Live probeProtocol surface
OAuth & OpenID Connect
These routes and capabilities passed startup configuration validation.
OIDC discovery
Publishes OpenID Connect discovery metadata
ConfigurationOAuth metadata
Publishes OAuth authorization server metadata
ConfigurationAuthorization Code + PKCE
Browser authorization with consent and PKCE protection
ConfigurationDevice Authorization
Supports user authorization for CLIs and input-constrained devices
ConfigurationClient Credentials
Issues service identities without an interactive user
ConfigurationToken introspection
Lets authorized clients inspect the current state of a token
ConfigurationToken revocation
Lets clients invalidate access and refresh tokens
ConfigurationUserInfo
Returns OpenID Connect claims for an authorized subject
ConfigurationJWT signing capability
The configured JWT signing capability is initialized
ConfigurationJSON Web Key Set
Publishes asymmetric public signing keys when the algorithm supports it
ConfigurationInstance choices
Optional features
Disabled capabilities are an instance choice, not a service failure.
Refresh tokens
Allows clients to renew access without another full sign-in
ConfigurationClient ID Metadata Documents (CIMD)
Accepts URL-shaped client IDs backed by self-hosted metadata documents
ConfigurationAudit logging
Records authentication, token, and administrative security events
ConfigurationPrometheus metrics
Exposes optional Prometheus operational metrics
ConfigurationLogin session tracking
Maintains server-side browser and device login sessions
ConfigurationRate limiting
Protects sensitive endpoints from excessive requests
ConfigurationRefresh token rotation
Replaces refresh tokens after each successful use
ConfigurationExternal OAuth login
At least one external identity provider is configured
Configuration