TU/e single sign-on (development)
Stands in for SURFconext. It authenticates people and issues identity tokens; it holds no notion of T-LIF roles. Reach it through a portal rather than directly — an authorization request needs a registered client and a PKCE challenge.
This service is permanent, not a placeholder. Local development and CI cannot reach TU/e SSO, so something has to issue tokens there. In production TLIF_IDP_ISSUER points at SURFconext instead and the portals do not change.
/authorize— sign-in and consent/token— authorization code exchange/.well-known/openid-configuration— discovery