jAccount Authorization Server (OAuth 2.0 / OpenID Connect)
SJTU's own identity and single sign-on system, run by the Network and Information Center on the university's own domain. It is a real OAuth 2.0 authorization server — an unparameterised GET of the authorize endpoint returned the correct RFC 6749 error on 2026-08-30 — and it publishes OpenID Connect provider metadata at /oauth2/.well-known/openid-configuration. Three grants are documented per operation: authorization code, client credentials and resource-owner password. The published scope registry runs to 39 scopes on a bitmask (1<