Testing ID Everywhere OIDC with Postman
Overview
Postman can be used to test an ID Everywhere OpenID Connect integration before connecting a production application.
This guide demonstrates the Authorization Code flow with PKCE, using a confidential test client.
This configuration has been successfully tested against ID Everywhere, including token retrieval and a UserInfo request.
Prerequisites
You will need:
-
Access to ID Everywhere.
-
An account permitted to create OIDC applications.
-
Postman with OAuth 2.0 authorization support.
-
An active ID Everywhere user for testing.
Never use production client secrets in screenshots or publicly shared Postman collections.
Step 1 — Register an OIDC test application
Sign in at:
Open your tenant's OIDC Applications management page.
Create an application with:
Application Name: Postman OIDC Test
Application Type: Web / Server Application (Confidential)
https://oauth.pstmn.io/v1/browser-callback
Save the application and securely record its Client ID and Client Secret.
Important: The Postman browser callback URL ends in /v1/browser-callback, not /v1/callback.
Step 2 — Open Postman's authorization settings
In Postman, create or open an HTTP request.
Choose the option to configure a new token.
Step 3 — Configure OAuth 2.0
Enter the following settings:
| Setting | Value |
|---|---|
| Grant Type | Authorization Code (With PKCE) |
| Callback URL | https://oauth.pstmn.io/v1/browser-callback |
| Authorization URL | https://app.ideverywhere.com/oauth2/authorize |
| Access Token URL | https://app.ideverywhere.com/oauth2/token |
| Client ID | Your IDE application's Client ID |
| Client Secret | Your IDE application's Client Secret |
| Scope | openid profile email |
| Code Challenge Method | SHA-256 / S256 |
| Client Authentication | Send as Basic Auth header |
The exact names of settings may vary slightly between Postman versions.
Why these settings matter
PKCE S256: Protects the authorization-code exchange.
Client Secret: Authenticates the confidential client to the token endpoint.
Scope: Requests OIDC authentication and identity information.
Basic Auth Header: Sends the confidential client's credentials using the supported client_secret_basic method.
Step 4 — Request an access token
Click Get New Access Token or the equivalent action in Postman.
Postman should open the ID Everywhere authorization page.
Sign in using your ID Everywhere account.
After authentication, Postman should receive the authorization response and exchange the code for tokens.
If successful, Postman displays the resulting token information.
Step 5 — Test the UserInfo endpoint
Create a new HTTP request in Postman.
Method: GET
URL:
https://app.ideverywhere.com/oauth2/userinfo
Alternatively, configure the request to use the OAuth 2.0 token already obtained in Postman.
Send the request.
Step 6 — Review the response
A successful UserInfo response may contain information similar to:
{
"sub": "example-unique-user-id",
"name": "Example User",
"given_name": "Example",
"family_name": "User",
"tenant_id": 2,
"role": "domain_admin",
"email": "[email protected]",
"email_verified": true
}
This is illustrative data. Actual values depend on the authenticated user and the granted scopes.
A successful response confirms that the access token was accepted by the UserInfo endpoint and that identity information was returned.
It does not, by itself, prove that a third-party application correctly validates ID tokens.
Common Postman errors
invalid_request
Verify that the Scope includes:
openid
This is required for OIDC authentication.
Also confirm the grant type, callback URL, and other required authorization parameters.
Redirect URL mismatch
Ensure the callback URL registered in ID Everywhere exactly matches the one used in Postman.
invalid_client
Verify the Client ID, Client Secret, and client authentication method.
For this confidential-client example, use Basic Auth header.
invalid_grant
No UserInfo response
Confirm that the request uses the access token, not the ID token or Client Secret.
Check whether the token is expired.
Testing public applications
For a public-client test:
-
Create a Public Application (PKCE) registration in ID Everywhere.
-
Register Postman's exact callback URL.
-
Select Authorization Code with PKCE S256.
-
Supply the Client ID.
-
Do not supply a Client Secret.
-
Use a client authentication method of None, where available.
-
Complete the authorization flow.
Security reminders
-
Do not publish Client Secrets.
-
Do not paste live tokens into support tickets.
-
Use dedicated test applications where possible.
-
Revoke or rotate exposed credentials.
-
Remove unused test registrations.
Related articles
-
Connecting an Application Using OIDC
-
Understanding OIDC Settings and Security Terms
-
Troubleshooting OIDC Connections