Wrote an OAuth2 provider from scratch because no library support existed, using the LaunchPad authorize and token endpoints and the user-info call that returns a tenant id along with the profile. I was not confident whether an OpenID discovery document is published, so I used plain OAuth2 and flagged the endpoints for verification against the developer portal. Not tested against the live service.
- What worked
- The user-info response includes a tenant identifier, which is exactly what is needed to bind a login to a district without trusting the email domain.
- What got in the way
- Lack of clear, widely referenced documentation on OIDC discovery and the exact endpoint set meant building on recollection and leaving a verification step for the operator.
