Phase 4: Building a Secure Next.js Identity Client

Phase 4 adds a Next.js and React web client to the Secure Identity & Trusted Data POC.

The client demonstrates how a modern browser application can integrate with the identity platform using OAuth Authorization Code, PKCE, JWT, and DPoP.

What I Built

  • Next.js + TypeScript client

  • OAuth Authorization Code flow

  • PKCE with S256

  • DPoP with ES256 / P-256

  • Secure API integration

  • Protected profile and identity pages

  • OAuth scope handling

  • Authentication and logout flows

  • Security and error handling

Architecture

Next.js / React
      ↓
OAuth + PKCE
      ↓
Identity Provider
      ↓
DPoP-bound JWT
      ↓
Protected Identity API
      ↓
PostgreSQL

This phase connects the previous backend components into a complete browser-to-API authentication flow.

Tech Stack: Next.js, React, TypeScript, C#, .NET 10, OAuth 2.1, PKCE, JWT, DPoP, PostgreSQL

GitHub: [VIEW SOURCECODE]

Related Posts

FlappyLove — Real-Time Multiplayer Browser Game ❤️

A playful real-time multiplayer browser game built with Next.js and TypeScript, featuring multiplayer rooms, synchronized gameplay, live scoring, and a Railway-hosted game server. ❤️

September 12, 2026·Marvin D. Verdera·Next.js, React

Phase 3: Securing OAuth Access Tokens with DPoP in ASP.NET Core

Phase 3 introduces DPoP sender-constrained access tokens to the Secure Identity & Trusted Data API, demonstrating ES256 proof-of-possession, JWT key binding, replay protection, OAuth scopes, and ASP.NET Core security architecture.

September 2, 2026·Marvin D. Verdera·API Integration, API Security, JWK, JWT, LLM

Phase 2: Building a Protected Identity & Trusted Data API with ASP.NET Core

Phase 2 extends the Secure Identity & Trusted Data API POC with a protected ASP.NET Core Resource Server, JWT/JWK validation, OAuth scopes, CQRS, Entity Framework Core, and PostgreSQL.

September 1, 2026·Marvin D. Verdera·API Security, JWK, JWT, PKCE, Identity Provider, API Integration