sgcAuth Feature Matrix

Everything sgcAuth does, mapped across the two client components, the grant types and claims they implement, and the WebAuthn, TOTP, LDAP, SAML, OpenID Connect and Mail OAuth2 components the pack unlocks together with sgcCustomIndy. Every capability works the same in Delphi and C++ Builder, and every license ships full source code.

OAuth2

Five grant types, one component

JWT

Sign, attach or verify

WebAuthn

Passkeys, via sgcCustomIndy

TOTP

Second factor codes and recovery codes

LDAP

Active Directory login over TLS

SAML

SAML 2.0 single sign-on

OpenID Connect

Sign in with ID token validation

Mail OAuth2

OAuth2 for SMTP, IMAP and POP3

Standards & Platforms

Delphi 7 to 13, C++ Builder

sgcAuth is self-contained. It ships with the sgcWebSockets Core runtime bundled in, so it is not an add-on for the OAuth2 and JWT clients.

Also inside sgcWebSockets. Both the OAuth2 Client and the JWT Client also ship inside sgcWebSockets editions from Standard up. All-Access includes everything. sgcAuth is the standalone package for teams that only need the authentication clients.

Seven Palette Components

Two token clients and five identity components, registered on the SGC Auth palette page.

ComponentClassJobDescription
OAuth2 ClientTsgcHTTP_OAuth2_ClientGet a tokenAuthorization Code, PKCE, Client Credentials, Resource Owner Password and Device Code grants against any OAuth2/OIDC provider, with a built-in local redirect server.
JWT ClientTsgcHTTP_JWT_ClientSign a tokenBuilds, signs and verifies JSON Web Tokens, standalone or as the Bearer token source for TsgcWebSocketClient, TsgcHTTP1Client and TsgcHTTP2Client.
TOTP AuthenticatorTsgcTOTPAuthenticatorCheck a second factorTOTP and HOTP secrets, otpauth QR provisioning, code verification with replay protection, and one-time recovery codes.
LDAP ClientTsgcLDAPClientCheck a directory passwordLDAP v3 and Active Directory sign-in over LDAPS or StartTLS, nested group membership and paged search.
SAML Service ProviderTsgcSAMLServiceProviderSingle sign-onSAML 2.0 service provider for Entra ID, Okta, AD FS, Google Workspace and Keycloak, with strict signature and assertion validation.
OpenID Connect ClientTsgcHTTP_OIDC_ClientSign in a userDiscovery, browser sign in with PKCE and nonce, ID token validation against the provider keys, and the userinfo endpoint.
Mail OAuth2TsgcMailOAuth2Authenticate mailAccess and refresh tokens for Microsoft 365 and Gmail, plus the SASL XOAUTH2 and OAUTHBEARER strings for SMTP, IMAP and POP3.

Five Grant Types, One Component

TsgcHTTP_OAuth2_Client covers OAuth 2.0 (RFC 6749) end to end: it starts the flow, catches the redirect, exchanges the code for a token, and manages the token afterward.

CapabilityAPINotes
Authorization CodeOAuth2Options.GrantType := auth2CodeThe standard flow for trusted server-side web applications that can hold a client secret.
Authorization Code + PKCEauth2CodePKCE (RFC 7636)The same flow with a Proof Key for Code Exchange, for native, mobile and single-page apps that cannot keep a secret.
Client Credentialsauth2ClientCredentialsServer-to-server calls with no user in the loop: daemons and service accounts.
Resource Owner Passwordauth2ResourceOwnerPasswordThe application collects the user's password directly and exchanges it for a token.
Device Codeauth2DeviceCode (RFC 8628)For input-constrained devices, smart TVs, media consoles, IoT: shows a user code the person enters on a second device.
Client identityOAuth2Options.ClientId, ClientSecret, Username, PasswordSet per your provider's API specification; Username/Password cover providers that require Basic Authentication on the token endpoint.
Provider endpointsAuthorizationServerOptions.AuthURL, TokenURL, Scope, RevocationURL, IntrospectionURLThe URLs and scope list published in your provider's OAuth2/OIDC documentation.
Social presetsTsgcHTTP_OAuth2_Client_Google, TsgcHTTP_OAuth2_Client_MicrosoftReady-made descendants that pre-configure the Google and Microsoft endpoints and scopes.
Local redirect listenerLocalServerOptions.IP, Port, RedirectURLThe small HTTP server the component starts to receive the authorization-code redirect; defaults to port 8080, or 0 to pick a random port for desktop apps.
Run the flowStart, StopStart opens the system browser (or issues the device code) and begins the configured grant; Stop aborts it and shuts the local listener.
RefreshRefreshExchanges a refresh token for a new access token without another browser round trip.
Revoke & introspectRevoke (RFC 7009), Introspect (RFC 7662)Invalidate a token, or query its status and metadata at the provider.
DPoPDPoPOptions, GenerateDPoPKeyPair, OnDPoPSignDemonstrating Proof-of-Possession (RFC 9449) key material and signing, for providers that bind tokens to a key pair.
HTTP transportHTTPClientOptionsTLS and logging configuration for the internal HTTP client that POSTs to the token, revocation and introspection endpoints.
Lifecycle eventsOnBeforeAuthorizeCode, OnAfterAuthorizeCode, OnBeforeAccessToken, OnAfterAccessToken, OnBeforeRefreshToken, OnAfterRefreshTokenBefore/after pairs around each step of the flow.
Error eventsOnErrorAccessToken, OnErrorAuthorizeCode, OnErrorRefreshToken, OnErrorRevokeToken, OnErrorIntrospectTokenOne per failure point in the flow, each carrying the provider's error, description and URI.
Device Code eventsOnDeviceCode, OnDeviceCodeExpiredDelivers the user code and verification URI to display, and fires if the user does not complete authorization in time.

Sign, Attach or Verify

TsgcHTTP_JWT_Client implements RFC 7519 (JSON Web Token), RFC 7515 (JWS) and RFC 7516 (JWE) through a single JWTOptions property.

CapabilityAPINotes
HeaderJWTOptions.Header.alg, typ, kidThe JOSE header. alg selects jwtHS256/384/512, jwtRS256/384/512, jwtES256/384/512 or the post-quantum jwtMLDSA44/jwtMLDSA65/jwtMLDSA87; extra fields go through Header.AddKeyValue.
Payload / claimsJWTOptions.Payload.iss, sub, aud, exp, nbf, iat, jtiThe registered RFC 7519 claims; custom claims are added with Payload.AddKeyValue.
Signing key materialJWTOptions.Algorithms.HS.Secret, RS.PrivateKey, ES.PrivateKey, MLDSA.PrivateKeyShared secret for HMAC, PEM-encoded private key for RSA or ECDSA, PKCS#8 PEM for ML-DSA, selected by Header.alg.
Post-quantum signaturesjwtMLDSA44, jwtMLDSA65, jwtMLDSA87The ML-DSA JWS algorithms of RFC 9964, implemented in pure Pascal, so no OpenSSL is involved on this path. The client signs with JWTOptions.Algorithms.MLDSA.PrivateKey, a PKCS#8 PEM; a server verifies with JWTOptions.Algorithms.MLDSA.PublicKey, a SubjectPublicKeyInfo PEM, once JWTOptions.Algorithms.MLDSA.Enabled is set.
ML-DSA JSON Web KeyssgcMLDSA_ExportPublicJWK, sgcMLDSA_ExportPrivateJWK, sgcMLDSA_ImportJWK, sgcMLDSA_ImportJWKAsPEMAKP JSON Web Keys, for publishing an ML-DSA key in a JWKS or reading one from a provider.
Auto-refreshJWTOptions.RefreshTokenAfterWhen greater than zero, Sign refreshes iat and recomputes exp automatically; 0 regenerates the token on every request.
Sign standaloneSignBuilds, signs and returns the encoded token (header.payload.signature) as a single string, no HTTP or WebSocket client required.
Attach to a clientStart, Client.Authentication.Token.JWTStart signs the configured JWT and delivers it as a Bearer token to the host component; set it once on Authentication.Token.JWT and every request goes out signed.
Works withTsgcWebSocketClient, TsgcHTTP1Client, TsgcHTTP2ClientAny of the three accepts a TsgcHTTP_JWT_Client as its Bearer token source through Authentication.Token.
OpenSSL configurationJWTOptions.OpenSSL_OptionsAPI version and library path used by the RS and ES algorithms (APIVersion, LibPath, LibPathCustom, UnixSymLinks).

Passwordless Sign-In, with One More Piece

WebAuthn is part of the sgcAuth story, but it is not a third registered component in this pack. It is served by the sgcWebSockets WebAuthn server, and it needs sgcCustomIndy underneath.

AreaDetail
What it isW3C Web Authentication Level 2 (WebAuthn): passwordless sign-in with passkeys and FIDO2 security keys, backed by TsgcWSAPIServer_WebAuthn.
Where it livesTsgcWSAPIServer_WebAuthn is a server-side component, part of sgcWebSockets Enterprise and All-Access, not a client registered by this pack.
What it needsThe patched Indy build that sgcCustomIndy ships as an add-on for sgcWebSockets Core.
How it is addedThe order page adds sgcCustomIndy to your cart automatically when you order sgcAuth. Already own a license? Remove the line at checkout, no extra charge either way.
Client sideA browser-side JavaScript application drives the WebAuthn ceremony; sgcHTML ships a ready-made WebAuthn login UI component that pairs with the server.
PasskeysUsernameless sign-in with discoverable credentials, passkey autofill through conditional mediation, several passkeys per user, synced or device-bound detection through BackupEligible and BackupState, and cloned authenticator detection.

Second Factor Codes, Each Accepted Once

TsgcTOTPAuthenticator implements TOTP (RFC 6238) and HOTP (RFC 4226), the codes shown by Google Authenticator, Microsoft Authenticator and every other authenticator app.

CapabilityAPINotes
SecretsGenerateSecret, SecretLengthA random Base32 secret, 20 bytes by default, to store with the user record.
QR provisioningGetProvisioningURI, IssuerBuilds the otpauth://totp/ URI with issuer, algorithm, digits and period, ready to render as a QR code.
Verify a codeVerifyCode, WindowAccepts the current time step and Window steps before or after it, 1 by default, so a phone clock a few seconds off still signs in.
Replay protectionVerifyCode with aLastTimeStepOnly accepts a time step greater than the last one used and returns the matched step, so a code can never be used twice.
HOTP countersGenerateHOTP, VerifyHOTPThe counter-based variant for hardware tokens, with a look-ahead window that resynchronises the counter on success.
Recovery codesGenerateRecoveryCodesFills any TStrings with unique one-time codes, the fallback when the user loses the device.
Algorithms and digitsAlgorithm, Digits, PeriodHMAC-SHA1, the default every app supports, HMAC-SHA256 or HMAC-SHA512, with codes of 6 to 8 digits and any period.

Active Directory Sign-In over TLS

TsgcLDAPClient is an LDAP v3 client (RFC 4511) that authenticates users against Active Directory or any other LDAP directory and reads their groups.

CapabilityAPINotes
ConnectionHost, Connect, BindDN, Password, BaseDNThe directory server, the service account used for searches, and the base of the user and group searches.
LDAPS and StartTLSSecurity, TLSOptionsldapsecLDAPS for implicit TLS on port 636 or ldapsecStartTLS on port 389. A refused StartTLS closes the connection, the client never falls back to clear text.
Sign-in modesAuthenticationMode, UserSearchFilterldapamUPN, ldapamDownLevel, ldapamSearchThenBind or ldapamDN turn the typed name into the bind name.
AuthenticateAuthenticateChecks the user name and password in one call and returns the DN of the user.
Nested groupsGetUserGroupsDirect memberOf values, or every group reached through other groups with the Active Directory rule LDAP_MATCHING_RULE_IN_CHAIN.
Paged searchSearch, PageSize, SizeLimit, TimeLimitSimple Paged Results are used automatically, 500 entries per page by default, and the entries and referrals come back in a TsgcLDAPEntries list.
Safe bindsBind, WhoAmI, LastResultCode, LastErrorMessageA DN with an empty password is refused without contacting the server, closing the unauthenticated bind hole of RFC 4513.
ThreadsEvery public methodCalls are serialized, so one instance can serve the login requests of a multi-threaded HTTP or WebSocket server.

SAML 2.0 Single Sign-On

TsgcSAMLServiceProvider makes a Delphi web application a SAML 2.0 service provider for Microsoft Entra ID, Okta, AD FS, Google Workspace, Keycloak and other identity providers.

CapabilityAPINotes
Service provider identityEntityID, AssertionConsumerServiceURLThe entity ID and the ACS URL that receives the responses posted by the browser.
Metadata both waysGetMetadata, LoadIdPMetadataGetMetadata produces the SP metadata to register in the IdP. LoadIdPMetadata fills IdPEntityID, IdPSSOURL, IdPSSOBinding and IdPCertificates.
Redirect and POST bindingsGetAuthnRequestRedirectURL, GetAuthnRequestPostFormThe HTTP-Redirect URL with the deflated AuthnRequest, or an auto-submitted HTTP-POST form.
Signed requestsSignAuthnRequests, SPCertificate, SPPrivateKeySigns the AuthnRequest for identity providers that require it.
Trusted keys onlyIdPCertificates, AllowSHA1Signatures are checked only against the configured IdP certificates, never a certificate embedded in the message. RSA-SHA256, RSA-SHA384 and RSA-SHA512 with exclusive canonicalization, SHA-1 only when allowed.
Signature wrapping protectionProcessResponseThe response must hold exactly one assertion as a direct child, and the signature must reference that element.
Assertion checksClockSkew, MaxAssertionAge, AllowIdPInitiatedIssuer, audience, destination, InResponseTo and the validity window are validated, with a replay cache of assertion IDs. IdP-initiated sign in stays off until enabled.
ResultTsgcSAMLResultNameID, NameIDFormat, SessionIndex, AuthnInstant, the Attributes with their friendly names, and a readable ErrorMessage.

Sign In with Any OpenID Provider

TsgcHTTP_OIDC_Client implements OpenID Connect Core 1.0 on top of the OAuth2 client, so the loopback redirect, refresh tokens, DPoP, device code, revocation and introspection all come along.

CapabilityAPINotes
DiscoveryOIDCOptions.Issuer, Discover, DiscoveryDocumentReads the provider configuration and fills the authorization and token URLs, JWKSURI, UserInfoEndpoint and EndSessionEndpoint.
Sign inStartOpens the browser and runs the Authorization Code flow through the local redirect server of the OAuth2 client.
PKCE and nonceOIDCOptions.UsePKCE, NoncePKCE is on by default and every sign in sends a fresh nonce that the ID token must echo.
ID token validationIDToken, IDTokenClaims, IDTokenValid, OnOIDCIDTokenSignature, issuer, audience, expiry with ClockSkew, and nonce are checked. Only RS256, RS384, RS512, ES256 and ES384 are accepted, none and the HS algorithms are always rejected.
Key rotationTsgcOIDCJWKS, RefetchIntervalA thread safe cache of the provider signing keys. An unknown key id triggers a new download, so key rotation needs no restart.
Server-side validationsgcOIDC_ValidateIDToken, OIDCOptions.AllowedTenantsValidates the bearer tokens your REST API or WebSocket server receives against the same key cache, and restricts multi-tenant Entra ID apps to the organizations you accept.
UserinfoGetUserInfoReturns the profile JSON of the signed-in user.

OAuth2 for SMTP, IMAP and POP3

TsgcMailOAuth2 gets and renews the tokens Microsoft 365 and Gmail expect for mail, and turns them into the SASL XOAUTH2 and OAUTHBEARER (RFC 7628) strings your mail client sends.

CapabilityAPINotes
Provider presetsProvider, TenantId, ClientIdmopMicrosoft365 or mopGmail with the right endpoints. mopCustom takes CustomAuthURL, CustomTokenURL, CustomDeviceAuthorizationURL and CustomScope.
Scopes from the protocolsProtocols, GetScopeAny mix of mpSMTP, mpIMAP and mpPOP3 requests the matching scopes, with offline_access on Microsoft 365.
Browser or device codeFlow, LocalServerOptions, OnDeviceCodemofAuthorizationCodePKCE opens the browser with a loopback redirect, mofDeviceCode suits services and consoles.
Token lifecycleStart, Refresh, AccessToken, RefreshToken, ExpiresAt, OnTokensChangedRefresh renews the access token synchronously and OnTokensChanged fires every time, so you can persist the new refresh token.
SASL stringsGetXOAuth2, GetOAuthBearerThe Base64 initial responses for AUTH XOAUTH2 and AUTH OAUTHBEARER. The Raw variants and the sgcGetXOAuth2 functions help with debugging and other token sources.
Transport agnosticHTTPClientOptionsThe component never opens a mail connection. Use Indy TIdSMTP, TIdIMAP4 or TIdPOP3, or any mail library that can send a raw SASL command.

RFCs, Compilers and Targets

Standards-track specs, and the same source across every supported compiler.

AreaDetail
OAuth2 standardsOAuth 2.0 (RFC 6749), PKCE (RFC 7636), Device Authorization Grant (RFC 8628), Token Revocation (RFC 7009), Token Introspection (RFC 7662), DPoP (RFC 9449).
JWT standardsJSON Web Token (RFC 7519), JSON Web Signature (RFC 7515), JSON Web Encryption (RFC 7516), ML-DSA for JOSE (RFC 9964).
WebAuthn standardWeb Authentication Level 2 (W3C), via the sgcWebSockets WebAuthn server.
Identity standardsTOTP (RFC 6238), HOTP (RFC 4226), LDAP v3 (RFC 4511), SAML 2.0 (OASIS), OpenID Connect Core 1.0, SASL OAUTHBEARER (RFC 7628) and XOAUTH2.
PlatformsBoth clients are plain HTTPS and local signing, so every Delphi platform is covered: Windows Win32/Win64, Linux 64-bit, macOS, iOS and Android.
CompilersDelphi and C++ Builder 7 through 13.
EditionsThe OAuth2 Client and JWT Client also ship inside sgcWebSockets from Standard up, the WebAuthn, TOTP, LDAP, SAML, OpenID Connect and Mail OAuth2 components in Enterprise, and All-Access includes everything.
LicensingStandalone. The sgcWebSockets Core runtime is bundled in and full source code is included.
Best value: All-AccessEvery eSeGeCe product, Premium Support included, from €1,059/year.
See All-Access pricing

Build with sgcAuth

Download the free trial and get your first access token or signed JWT from Delphi or C++ Builder.