Wand Identity (OpenID Connect)
Wand runs Keycloak at auth.wand.ai as the identity provider for its platform. The master realm serves an anonymous OpenID Connect discovery document declaring the authorization, token, userinfo, introspection, revocation, device-authorization and JWKS endpoints, the supported grant types and response modes, and the supported scopes. Client registration and every token endpoint require credentials; only the discovery metadata and JWKS are public.