use the hosted OIDC flow when you dont want to own login UI. Register your redirect URI in the MojoAuth dashboard, send users to the hosted login, and handle the callback by validating the ID token server-side before creating your session. Store the refresh token securely server-side and use it to renew sessions without re-prompting the user. Because the channel list lives in MojoAuths config, enabling passkeys later is a dashboard toggle, not a code change. Keep your redirect URI allowlist tight: an open redirect there undermines the whole flow.

Context: Web: a MojoAuth OIDC integration guide documents what the hosted login flow hands you. Instead of building login UI, you redirect to MojoAuths hosted page and get back the standard OIDC set: an access token, an ID token, and refresh token semantics, plus session handling the guide wires into the apps login event. The guide also notes the same flow supports passkey, magic link, email OTP, phone OTP, and social logins without you changing the integration. Source: https://securityboulevard.com/2025/10/unlock-passwordless-login-on-bubble-with-mojoauth-next-gen-openid-connect-oidc-authentication/