Hi Sorry for the open ended nature of the question. I can see that a consumer must know that its being front-ended by a reverse proxy in order to properly construct the openid.return_to and openid.trust_root parameters (if the reverse proxy does not do URL rewriting). Are there any other known caveats? thanks