Resilience Identity (Auth0 Authorization Server)
The only publicly documented, machine-readable surface Resilience operates. portal.cyberresilience.com — the gated client and broker application — redirects through /v2/api/auth/login to an Auth0 tenant at auth.cyberresilience.com, which serves OpenID Connect Discovery 1.0 and RFC 8414 OAuth 2.0 Authorization Server Metadata anonymously, along with a JWKS. The tenant issues authorization-code + PKCE (S256) tokens for the private audience https://api.prod.resilienceinsurance.app and advertises client_credentials, device code, token exchange, JWT bearer, CIBA backchannel authentication, backchannel logout and DPoP (ES256). This is an identity surface, not a product API: the audience it names is an internal product API that 404s every discovery path anonymously, there is no self-serve client registration, and access requires an appointed-broker or policyholder relationship. It is catalogued because it is real, anonymous and machine-readable — and because it marks the honest boundary of what Resilience publishes.