Discovery: GET https://navcom.ai/.well-known/openid-configuration OpenAPI: GET https://navcom.ai/oauth/openapi.json JWKS: GET https://navcom.ai/oauth/jwks.json (RS256; not the portal cookie key) Authorization Code + PKCE S256 only: GET /oauth/authorize POST /oauth/token (authorization_code, refresh_token; refresh tokens rotate) GET /oauth/userinfo (bearer) POST /oauth/introspect (RFC 7662, confidential clients only) POST /oauth/revoke (RFC 7009) GET /oauth/v1/me GET /oauth/v1/me/orgs GET /oauth/v1/resolve/rsi/{handle} GET /oauth/v1/resolve/discord/{id} (consent + discover toggle) GET /oauth/v1/resolve/rsi/{handle}/discord (consent + discover toggle) GET /oauth/v1/citizens/{handle}/avatar (public, no token, rate limited; 302 to SENTRY) GET /oauth/v1/apps (approved name, homepage, scopes) GET /oauth/v1/apps/{client_id}/tokens (developer inventory; client secret) POST /oauth/v1/apps/{client_id}/tokens/{token_id}/revoke POST /oauth/revoke Token auth methods: client_secret_post, client_secret_basic, private_key_jwt, none (public PKCE clients). required_scope= marks required claims (space-separated). If omitted, every requested scope is required. openid is always required. Reasons (plain text, 240 chars, HTML stripped): reason= overall reason_orgs= / reason_rsi= / reason_email= / reason_rsi_enlisted=