OptionalcodePKCE code verifier associated with the authorization request.
OptionalfetchWhen enabled, user profile data is fetched from the UserInfo endpoint and merged into the session user object.
OptionalfilteredList of ID token claims to remove before storing the session.
OptionalidClock skew adjustment (in seconds) applied when validating ID token timestamps against the authorization server.
OptionalidAdditional allowed clock tolerance (in seconds) when validating time-based ID token claims such as exp, iat, and nbf.
OptionalidMaximum allowed authentication age (in seconds) for the ID token.
OptionalidNonce value expected in the ID token. Used to prevent replay attacks.
OptionaljwksJSON Web Key Set used to validate the ID token signature.
If not provided, the JWKS is automatically fetched from the authorization server metadata.
OptionalonCallback invoked before a session is created or updated. Allows customization or enrichment of the session.
OptionalvalidateDetermines whether the ID token signature and claims should be validated. Disabling validation is not recommended except for advanced or controlled environments.
Options used when authenticating a user via the Authorization Code flow.