Authorization Manager plugins are described by a {@link se.curity.identityserver.sdk.plugin.descriptor.AuthorizationManagerPluginDescriptor}.
Data Access Provider plugins implement the {@link se.curity.identityserver.sdk.plugin.descriptor.DataAccessProviderPluginDescriptor} interface. Samples can be found on GitHub.
SMS sender plugins implement the {@link se.curity.identityserver.sdk.plugin.descriptor.SmsPluginDescriptor} interface. Samples can be found on GitHub.
Email sender plugins implement the {@link se.curity.identityserver.sdk.plugin.descriptor.EmailProviderPluginDescriptor} interface. Samples can be found on GitHub.
They provide handlers for anonymous requests (such that users can, for example, access login and registration pages), as well as handlers of the actual logic for authentication and registration. Samples can be found on GitHub.
Back-channel authenticators are described by the {@link se.curity.identityserver.sdk.plugin.descriptor.BackchannelAuthenticatorPluginDescriptor}. An example can be found on GitHub.
These type of plug-ins provide the "steps" within a workflow that execute after login or SSO. Samples can be found on GitHub.
The {@link se.curity.identityserver.sdk.plugin.descriptor.EventListenerPluginDescriptor} class describes this type of plugin. Samples can be found on GitHub.
A consentor is a plugin that runs after user consent has taken place in an OAuth flow. It implements additional logic that verifies the consent prior to it being granted. A specialized type of consentor is a Signing Consentor. Because this specialization is so common, a subtype exists to simplify the development of this kind of consentor. A general consentor plugin will implement the {@link se.curity.identityserver.sdk.plugin.descriptor.ConsentorPluginDescriptor} interface and signing consentors will implement {@link se.curity.identityserver.sdk.plugin.descriptor.SigningConsentorPluginDescriptor}. Samples can be found on GitHub.
When tokens are issued and claims need to be added to them, the values can be obtained from Claims Providers. This kind of plugin will implement the {@link se.curity.identityserver.sdk.claims.ClaimsProvider} interface. This is made know to the run-time environment by implementing an instance of the {@link se.curity.identityserver.sdk.plugin.descriptor.ClaimsProviderPluginDescriptor} interface.
When an alarm is raised for the first time, its severity changes, or when it is cleared, the Alarm Handler is invoked. This kind of plugin will implement the {@link se.curity.identityserver.sdk.plugin.descriptor.AlarmHandlerPluginDescriptor} interface. It can choose to handle the alarm directly itself, or forward the message to some other system (e.g., a NMS or NOC). An Alarm Handler that forwards the alarm info rather than handling it directly, is referred to as an Alarm Notifier.
A plugin defines its configuration by declaring an interface extending the {@link se.curity.identityserver.sdk.config.Configuration} interface in its descriptor.