sgcAuth: OAuth2, JWT & WebAuthn Components for Delphi & C++ Builder
Two client components carry the token side of modern authentication into your application. TsgcHTTP_OAuth2_Client runs the Authorization Code, PKCE, Client Credentials, Resource Owner Password and Device Code grants against any OAuth2/OIDC provider. TsgcHTTP_JWT_Client builds, signs and verifies JSON Web Tokens, on its own or as the Bearer token source for your WebSocket and HTTP clients. Five more components add TOTP second factors, LDAP and Active Directory login, SAML single sign-on, OpenID Connect and OAuth2 for mail. sgcAuth is standalone, it bundles the sgcWebSockets Core runtime both clients are built on.
Bundled runtimesgcWebSockets CoreThe HTTP, TLS and JSON runtime under both clients
OAuth2TsgcHTTP_OAuth2_Client
JWTTsgcHTTP_JWT_Client
WATCH IT WORK
See sgcAuth in Two Minutes
OAuth2, JWT and WebAuthn passkeys in Delphi and C++Builder, on the client and in your own server.
7ComponentsOne page on the component palette
9RFCs implementedOAuth2, PKCE, DPoP, Device Code, JWT/JWS/JWE and more
5PlatformsWindows, macOS, Linux, iOS and Android
100%Source code includedBoth clients and the bundled Core runtime
12Months of updatesEvery release published while your license is active
BEFORE YOU BUY
Three Things Worth Knowing First
What sgcAuth needs from you, whether you already own these components, and what WebAuthn needs on top. All three answers are short.
sgcAuth is self-contained
Standalone, the sgcWebSockets Core runtime is included: the HTTP/TLS client stack both components POST their token requests through, and the JSON machinery that parses the responses. One SKU, one installer.
Full source code ships with every license, so both clients and the runtime under them step through in your own debugger rather than disappearing into a binary.
Edition overlap
Already in your sgcWebSockets edition?
Both the OAuth2 Client and the JWT Client ship inside sgcWebSockets from the Standard edition up, so if you own any sgcWebSockets edition you already have both components. The WebAuthn, TOTP, LDAP, SAML, OpenID Connect and Mail OAuth2 components ship in Enterprise. All-Access includes everything.
sgcAuth exists for the opposite case: you want OAuth2 and JWT client support in Delphi or C++ Builder without licensing a full sgcWebSockets edition. Check what your edition already covers before you buy.
Add-on required
WebAuthn needs sgcCustomIndy
Passwordless sign-in with WebAuthn and passkeys is served by TsgcWSAPIServer_WebAuthn, a sgcWebSockets Enterprise/All-Access component built on the patched Indy library that sgcCustomIndy ships as an add-on. WebAuthn requires the sgcCustomIndy add-on, which is added automatically when you order sgcAuth. The TOTP, LDAP, SAML, OpenID Connect and Mail OAuth2 components are unlocked by the same add-on.
Already own a sgcCustomIndy license? Remove the automatically added line from your cart before checkout, no extra charge either way.
WHAT IS IN THE BOX
Token Clients, Second Factors and Single Sign-On
Each one is a non-visual component you drop on a form or create in code, declared under the sgc unit prefix and registered on the SGC Auth palette page. Set the provider details, wire the events, then call Start. The TOTP, LDAP, SAML, OpenID Connect and Mail OAuth2 components are unlocked together with sgcCustomIndy, like WebAuthn.
OAuth21 component
Five grant types, one component
TsgcHTTP_OAuth2_Client drives OAuth2Options.GrantType through auth2Code for trusted server-side apps, auth2CodePKCE for native, mobile and single-page apps, auth2ClientCredentials for daemons and service accounts, auth2ResourceOwnerPassword, and auth2DeviceCode (RFC 8628) for smart TVs, kiosks and other input-constrained devices. Point AuthorizationServerOptions at the provider's authorize, token, revocation and introspection endpoints and the component handles the rest: when Active/Start runs the Authorization Code flow, it opens the system browser and stands up a small local HTTP server from LocalServerOptions to catch the redirect, exchanging the code for a token over plain HTTPS through HTTPClientOptions. Refresh, Revoke and Introspect cover the token lifecycle after that, and DPoPOptions plus GenerateDPoPKeyPair add DPoP proof-of-possession (RFC 9449) for providers that require it. Ready-made Google and Microsoft presets configure the common endpoints and scopes for you.
TsgcHTTP_JWT_Client publishes everything RFC 7519 needs through JWTOptions: the JOSE Header (alg, typ, kid), the registered Payload claims (iss, sub, aud, exp, nbf, iat, jti, plus custom claims through AddKeyValue), and the key material under Algorithms for HMAC (HS.Secret), RSA (RS.PrivateKey) and ECDSA (ES.PrivateKey). Call Sign to get the compact-serialization token back directly, useful for services with no built-in HTTP or WebSocket client, or set RefreshTokenAfter and let the component refresh iat/exp and re-sign automatically. The same component plugs straight into Authentication.Token.JWT on TsgcWebSocketClient, TsgcHTTP1Client and TsgcHTTP2Client, so every outbound request carries a fresh Bearer token without you touching the header yourself.
TsgcTOTPAuthenticator adds the six digit codes of any authenticator app, Google Authenticator and Microsoft Authenticator included, to your sign-in. GenerateSecret creates a random Base32 secret and GetProvisioningURI builds the otpauth:// URI you render as a QR code during enrolment. VerifyCode checks what the user types with a configurable Window for clock drift, and its replay-protected overload never accepts the same time step twice. GenerateHOTP and VerifyHOTP cover counter-based hardware tokens, GenerateRecoveryCodes fills a list of one-time fallback codes, and Algorithm, Digits and Period select HMAC-SHA1, HMAC-SHA256 or HMAC-SHA512 with codes of 6 to 8 digits.
TsgcLDAPClient is an LDAP v3 client that checks user names and passwords against Active Directory or any other LDAP directory. Security selects LDAPS on port 636 or StartTLS on port 389, and a refused StartTLS closes the connection instead of falling back to clear text. AuthenticationMode turns what the user typed into a bind name, as a UPN, a DOMAIN\user name, a full DN, or a service bind followed by a search with UserSearchFilter, and Authenticate does the whole check in one call. GetUserGroups returns direct or nested group membership through LDAP_MATCHING_RULE_IN_CHAIN, Search pages large result sets automatically, and every public method is serialized, so one instance can serve a multi-threaded server.
TsgcSAMLServiceProvider makes your Delphi web application a SAML 2.0 service provider for Microsoft Entra ID, Okta, AD FS, Google Workspace, Keycloak and other identity providers. GetMetadata produces the metadata you register at the IdP and LoadIdPMetadata reads theirs. GetAuthnRequestRedirectURL and GetAuthnRequestPostForm send the browser to sign in over the Redirect or POST binding, and ProcessResponse validates what comes back: the signature only against the trusted IdPCertificates, exactly one assertion to defeat signature wrapping, then issuer, audience, destination, InResponseTo, the validity window and a replay cache. The outcome arrives as a TsgcSAMLResult with the NameID, the session index and the attributes.
TsgcHTTP_OIDC_Client extends the OAuth2 client with OpenID Connect. Set OIDCOptions.Issuer and Discover fills the endpoints and the JWKSURI from the provider configuration. Start runs the browser sign in with PKCE and a fresh nonce, then validates the ID token signature, issuer, audience, expiry and nonce, accepting only RS256, RS384, RS512, ES256 and ES384 and never none or the HS algorithms. OnOIDCIDToken delivers the claims, GetUserInfo returns the profile, and a thread safe key cache follows key rotation without a restart. On the server side, sgcOIDC_ValidateIDToken checks the bearer tokens your REST API or WebSocket server receives against the same cache.
TsgcMailOAuth2 gets the tokens Microsoft 365 and Gmail expect for mail. Choose the Provider (mopMicrosoft365, mopGmail or mopCustom) and the Protocols you use, and the component requests the matching scopes. Flow runs the browser sign in with PKCE and a loopback redirect, or the device code flow for services and consoles. Refresh renews the access token and OnTokensChanged fires every time, so you can store the new refresh token. GetXOAuth2 and GetOAuthBearer return the SASL strings for AUTH XOAUTH2 and AUTH OAUTHBEARER, ready for Indy TIdSMTP, TIdIMAP4 and TIdPOP3 or any other mail library.
TsgcMailOAuth2RFC 7628 · XOAUTH2 · Microsoft 365 · Gmail
USE CASES
Authentication Flows from Delphi Code
Both components are ordinary non-visual components, so they slot into whatever your application already is: a VCL desktop app, a Windows service, a Linux daemon. These are the patterns customers build, each mapped to the property or method that drives it.
SI
Sign in with Google or Microsoftauth2CodePKCE
Ready-made Google and Microsoft presets configure the authorize and token endpoints and scopes for you.
M2
Server-to-server API accessauth2ClientCredentials
Background jobs and service accounts authenticate to an API without a user in the loop.
TV
Smart TVs, kiosks & IoT devicesauth2DeviceCode
The device shows a short code, the user finishes sign-in on their phone or laptop.
RF
Long sessions without re-promptingRefresh
Exchange a refresh token for a new access token behind the scenes, no browser hand-off needed.
WS
Authenticate your own WebSocket & HTTP APIsAuthentication.Token.JWT
The JWT Client signs Bearer tokens for TsgcWebSocketClient, TsgcHTTP1Client and TsgcHTTP2Client automatically.
SG
Stand-alone token signingSign
Build and sign a JWT string for any codebase, no WebSocket or HTTP component required.
HOW IT WORKS
A Browser Hand-Off, a Signature, and a Bundled Runtime
OAuth2 and JWT solve different problems, one negotiates a token with a remote server, the other signs one locally, and that is the point of packaging them together: sgcAuth hides the difference behind the same component conventions, with the bundled sgcWebSockets Core runtime doing the plumbing underneath.
OAuth2 is a browser hand-off, then plain HTTPS
Start opens the system browser (or, for Device Code, hands you the user code to display) and a local HTTP listener from LocalServerOptions catches the authorization redirect. The exchange for the access token is a plain HTTPS POST issued through HTTPClientOptions, on the Core runtime's HTTP client stack.
JWT is signing, not networking
TsgcHTTP_JWT_Client never opens a socket. JWTOptions configures the header, payload and key material, and Sign returns the compact-serialization token, HMAC, RSA or ECDSA, ready to attach to any request your own code sends.
The Core runtime is in the box
Standalone, the sgcWebSockets Core runtime is included. It contributes the HTTP/TLS client stack both components POST through and the JSON parser that reads the responses, and its full source is part of the package like everything else.
WebAuthn is the third piece, via sgcCustomIndy
Passwordless sign-in is handled by TsgcWSAPIServer_WebAuthn, a sgcWebSockets Enterprise/All-Access server component that needs the patched Indy build sgcCustomIndy ships. Ordering sgcAuth adds sgcCustomIndy to your cart automatically.
QUICK START
Get a Token, Sign a Token
Both components follow the same shape: configure the options, then call a method. They compile in Delphi 7 to 13 and C++ Builder, and the same properties are exposed on .NET.
uses
sgcHTTP, sgcHTTP_OAuth_Types, sgcHTTP_JWT_Types;
var
OAuth2: TsgcHTTP_OAuth2_Client;
JWT: TsgcHTTP_JWT_Client;
begin// OAuth2: Authorization Code Grant with PKCE
OAuth2 := TsgcHTTP_OAuth2_Client.Create(nil);
OAuth2.OAuth2Options.GrantType := auth2CodePKCE;
OAuth2.OAuth2Options.ClientId := 'your-client-id';
OAuth2.AuthorizationServerOptions.AuthURL := 'https://provider.com/oauth2/authorize';
OAuth2.AuthorizationServerOptions.TokenURL := 'https://provider.com/oauth2/token';
OAuth2.AuthorizationServerOptions.Scope.Clear;
OAuth2.AuthorizationServerOptions.Scope.Add('openid');
OAuth2.AuthorizationServerOptions.Scope.Add('profile');
OAuth2.LocalServerOptions.IP := '127.0.0.1';
OAuth2.LocalServerOptions.Port := 8080;
OAuth2.OnAfterAccessToken := OAuth2AccessToken;
OAuth2.Start; // opens the browser; the redirect lands on the local server// JWT: sign a token for your own API
JWT := TsgcHTTP_JWT_Client.Create(nil);
JWT.JWTOptions.Header.alg := jwtHS256;
JWT.JWTOptions.Algorithms.HS.Secret := '79F66F1E-E998-436B-8A0A-3E5DEFA4FD9E';
JWT.JWTOptions.Payload.iss := 'your-service';
JWT.JWTOptions.Payload.sub := '1234567890';
JWT.JWTOptions.Payload.iat := DateTimeToUnix(Now);
ShowMessage(JWT.Sign);
end;
procedure TForm1.OAuth2AccessToken(Sender: TObject; const Access_Token,
Token_Type, Expires_In, Refresh_Token, Scope, RawParams: String;
var Handled: Boolean);
begin
Memo1.Lines.Add('Access token received.');
end;
The same JWT component attaches to a WebSocket or HTTP client directly: set Client.Authentication.Token.Enabled := True and Client.Authentication.Token.JWT := JWT, and every request goes out with a fresh Bearer token.
// include: sgcHTTP.hpp, sgcHTTP_OAuth_Types.hpp, sgcHTTP_JWT_Types.hpp// OAuth2: Authorization Code Grant with PKCE
TsgcHTTP_OAuth2_Client *OAuth2 = new TsgcHTTP_OAuth2_Client(this);
OAuth2->OAuth2Options->GrantType = auth2CodePKCE;
OAuth2->OAuth2Options->ClientId = "your-client-id";
OAuth2->AuthorizationServerOptions->AuthURL = "https://provider.com/oauth2/authorize";
OAuth2->AuthorizationServerOptions->TokenURL = "https://provider.com/oauth2/token";
OAuth2->AuthorizationServerOptions->Scope->Clear();
OAuth2->AuthorizationServerOptions->Scope->Add("openid");
OAuth2->AuthorizationServerOptions->Scope->Add("profile");
OAuth2->LocalServerOptions->IP = "127.0.0.1";
OAuth2->LocalServerOptions->Port = 8080;
OAuth2->OnAfterAccessToken = OAuth2AccessToken;
OAuth2->Start(); // opens the browser; the redirect lands on the local server// JWT: sign a token for your own API
TsgcHTTP_JWT_Client *JWT = new TsgcHTTP_JWT_Client(this);
JWT->JWTOptions->Header->alg = jwtHS256;
JWT->JWTOptions->Algorithms->HS->Secret = "79F66F1E-E998-436B-8A0A-3E5DEFA4FD9E";
JWT->JWTOptions->Payload->iss = "your-service";
JWT->JWTOptions->Payload->sub = "1234567890";
JWT->JWTOptions->Payload->iat = DateTimeToUnix(Now());
ShowMessage(JWT->Sign());
void __fastcall TForm1::OAuth2AccessToken(TObject *Sender,
const UnicodeString Access_Token, const UnicodeString Token_Type,
const UnicodeString Expires_In, const UnicodeString Refresh_Token,
const UnicodeString Scope, const UnicodeString RawParams, bool &Handled)
{
Memo1->Lines->Add("Access token received.");
}
The same JWT component attaches to a WebSocket or HTTP client directly: set Client->Authentication->Token->Enabled = true and Client->Authentication->Token->JWT = JWT, and every request goes out with a fresh Bearer token.
PLATFORMS
Pure HTTPS and Signing, No Native Library
Neither component depends on anything beyond the Core runtime's HTTP client stack and the platform's crypto primitives, so both compile and run wherever Delphi does.
sgcAuth is licensed on its own, starting at €149 for a single developer. All licenses include full source code, 1 year of updates and a 50% to 70% renewal discount: 50% when you renew one pack, 60% for two, 70% for three or more. sgcAI, sgcMQ, sgcSocial, sgcCustomIndy, sgcAuth, sgcHTTP and sgcREST each count as a pack.
Checkout lists two items: the sgcWebSockets Core runtime entitlement, which is charged at zero, and the sgcAuth pack itself. sgcCustomIndy is added automatically for WebAuthn, remove it if you already own a license. Full pricing details.
3,000+Developers
20+Years
761+Components
30+API Integrations
5Platforms
30-Day Money-Back GuaranteeNot satisfied? Request a full refund within 30 days of purchase. See refund policy
Ship Authentication, Not a Token Library
OAuth2 and JWT from native Delphi and C++ Builder code, with the runtime bundled in and full source code in the box. Download the All-Access trial installer and drop both components on a form today.