Phase 4 adds a Next.js and React web client to the Secure Identity & Trusted Data POC.
The client demonstrates how a modern browser application can integrate with the identity platform using OAuth Authorization Code, PKCE, JWT, and DPoP.
What I Built
Next.js + TypeScript client
OAuth Authorization Code flow
PKCE with S256
DPoP with ES256 / P-256
Secure API integration
Protected profile and identity pages
OAuth scope handling
Authentication and logout flows
Security and error handling
Architecture
Next.js / React
↓
OAuth + PKCE
↓
Identity Provider
↓
DPoP-bound JWT
↓
Protected Identity API
↓
PostgreSQLThis phase connects the previous backend components into a complete browser-to-API authentication flow.
Tech Stack: Next.js, React, TypeScript, C#, .NET 10, OAuth 2.1, PKCE, JWT, DPoP, PostgreSQL
GitHub: [VIEW SOURCECODE]
