OAuth & API Usage Policy
Effective Date: September 19, 2026
Last Updated: September 19, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Overview & Scope
This OAuth 2.0 & API Usage Policy governs technical access to Startum's authentication endpoints, OpenID Connect discovery endpoints, userinfo APIs, and developer administration endpoints.
All applications registering for client credentials or issuing API requests to Startum servers must comply with this policy.
2. Client Application Registration Standards
A. Client Types
When registering an application in the Startum Developer Portal, developers must accurately select the Client Type:
- Confidential Client: Backend applications running on server infrastructure where the
client_secretcan be stored securely without exposure to end-user devices. - Public Client: Applications running on client devices (SPAs, mobile apps, native desktop software) where credentials cannot be guaranteed secure. Public clients receive no
client_secretand must authenticate code exchanges exclusively using PKCE (RFC 7636).
B. Strict Redirect URI Validation
- Exact Matching: Startum enforces strict string matching on redirect URIs. Wildcard domain patterns (
https://*.domain.com), fragment identifiers, or open redirects are strictly rejected. - HTTPS Enforcement: Production applications must use secure
https://URLs for all redirect URIs. Non-securehttp://URLs are permitted exclusively forlocalhostor loopback IPv4/IPv6 addresses (http://127.0.0.1,http://[::1]).
3. Token Lifespans & Management
Startum issues standardized tokens with explicit validity windows:
| Token Type | Lifespan | Format | Description |
|---|---|---|---|
| Authorization Code | 10 Minutes | Cryptographic Code | Single-use code exchanged via /oauth/token. |
| Access Token | 1 Hour (3,600s) | RS256 Signed JWT | Bearer token used to query /oauth/userinfo. |
| ID Token | 1 Hour (3,600s) | RS256 Signed JWT | OpenID Connect identity assertion token. |
| Refresh Token | 30 Days | Cryptographic Opaque | Rotated token used to request new access tokens. |
Refresh Token Rotation
Startum implements Refresh Token Rotation. When a refresh token is used to acquire a new access token, a new refresh token is issued, and the previous refresh token is immediately invalidated. If a previously consumed refresh token is presented again, Startum detects potential token theft and immediately revokes all active tokens associated with that authorization grant.
4. API Rate Limits & Quotas
To protect infrastructure availability and ensure equitable access, Startum enforces rate limits on standard API endpoints:
| Endpoint Group | Rate Limit Window | Maximum Allowed Requests |
|---|---|---|
Authorization (/oauth/authorize) |
1 Minute | 100 requests per IP |
Token Exchange (/oauth/token) |
1 Minute | 60 requests per IP / Client ID |
UserInfo (/oauth/userinfo) |
1 Minute | 300 requests per Access Token |
Developer APIs (/api/apps) |
1 Minute | 120 requests per Developer Session |
Exceeding these limits results in an HTTP response status 429 Too Many Requests containing standard Retry-After headers.
5. Security & Auditing Standards
- Client Secret Exposure: If a Confidential Client's secret is leaked or exposed publicly, the developer must regenerate the secret immediately in the Developer Portal.
- JWKS Verification: Resource servers verifying Startum ID Tokens must fetch public RSA signing keys from the official JWKS endpoint (
https://api.startum.cloud/.well-known/jwks.json) and cache keys respecting standard HTTPCache-Controlheaders. - Auditing Rights: Startum reserves the right to audit registered client applications to verify compliance with scope usage, privacy policies, and security practices.
6. Policy Updates & Inquiries
For questions regarding API rate limits, custom quotas, or OAuth integration policy:
Email: [email protected]
Developer Portal: https://develop.startum.cloud