# Your first sign-in

> Sign in to the OneiD demo application, read the discovery document of the demonstration instance and pick a quickstart.

Source: https://oltinid.com/docs/get-started/first-sign-in/ · Section: Get started · All OneiD documentation: https://oltinid.com/llms.txt

Before you connect your own application, see a OneiD sign-in from the user's side and look at what OneiD publishes about itself. This page uses the demonstration instance that we run at `https://auth.oltinid.com`.

## What you need

- A web browser.
- A terminal with `curl`. `jq` is optional and makes the JSON easier to read.
- A demo account. [Ask for one](https://oltinid.com/contact/?topic=demo) through the contact page.

## Step 1: Sign in to the demo application

`https://demo.oltinid.com` is a small application that signs in through the demonstration instance and shows you the tokens it receives.

1. Open `https://demo.oltinid.com` in your browser.
2. Choose to sign in. The browser moves to `https://auth.oltinid.com`, which shows the OneiD sign-in page.
3. Sign in with your demo account. If the account has MFA set up, enter the code from your authenticator app.
4. If OneiD shows a consent page, review the scopes and continue.
5. The browser returns to the demo application, which shows your tokens and their claims.

Look at the requests during step 2, for example in the network tab of your browser's developer tools. The first request to OneiD goes to `https://auth.oltinid.com/connect/authorize` and carries parameters such as `client_id`, `redirect_uri`, `scope`, `state` and `code_challenge`. This is the authorisation request every application sends.

> **Checkpoint:** The demo application shows an ID token whose `iss` is `https://auth.oltinid.com/`, with the trailing slash, and whose `sub` identifies your demo account.

### What to look for in the tokens

| Claim | Where | What it tells you |
|---|---|---|
| `iss` | ID token and access token | Which OneiD issued the token. Ends with a slash. |
| `sub` | ID token and access token | The user's stable, opaque identifier. |
| `aud` | ID token | The client ID of the demo application. |
| `auth_time` | ID token | When you signed in, in seconds since 1970. |
| `amr` | ID token | How you signed in, for example `["pwd"]` or `["pwd","mfa"]`. |
| `acr` | ID token | The same information as one value, for example `urn:oltin:ac:pwd`. |
| `scope` | Access token | The scopes the access token carries, separated by spaces. |
| `idp` | ID token and access token, with `profile` | Where you signed in. On the demonstration instance this is `local`. |

The access token has no `aud` claim. APIs check its issuer, signature, expiry and scope instead. See [Tokens](https://oltinid.com/docs/reference/tokens/).

### Single sign-on

After you sign in, OneiD keeps a session in your browser for 8 hours, extended while you are active. While it lasts, any other application that sends you to the same OneiD signs you in without asking for your password again.

## Step 2: Read the discovery document

Every OneiD instance publishes a discovery document that lists its endpoints and capabilities. OpenID Connect libraries read it to configure themselves.

```bash
curl -s https://auth.oltinid.com/.well-known/openid-configuration | jq
```

The response is a JSON object. These are some of the fields you will see (abridged):

```json
{
  "issuer": "https://auth.oltinid.com/",
  "authorization_endpoint": "https://auth.oltinid.com/connect/authorize",
  "token_endpoint": "https://auth.oltinid.com/connect/token",
  "userinfo_endpoint": "https://auth.oltinid.com/connect/userinfo",
  "end_session_endpoint": "https://auth.oltinid.com/connect/logout",
  "jwks_uri": "https://auth.oltinid.com/.well-known/jwks",
  "response_types_supported": ["code"],
  "response_modes_supported": ["form_post", "fragment", "query"],
  "grant_types_supported": ["authorization_code", "client_credentials", "refresh_token"],
  "subject_types_supported": ["public"],
  "id_token_signing_alg_values_supported": ["RS256"],
  "claims_parameter_supported": true,
  "request_parameter_supported": false,
  "request_uri_parameter_supported": false,
  "authorization_response_iss_parameter_supported": true
}
```

What this tells you:

- **`issuer`** ends with a slash. Tokens carry exactly this value in `iss`.
- **`response_types_supported`** is `code` only. Applications use the authorization code flow.
- **`grant_types_supported`** lists the three grants OneiD supports. There is no password grant and no device flow.
- **`authorization_response_iss_parameter_supported`** is `true`. OneiD adds `iss` to the redirect back to your application, so you can check that the response came from the OneiD you called.
- **`request_parameter_supported`** is `false`. OneiD does not accept request objects.

Now fetch the public signing keys:

```bash
curl -s https://auth.oltinid.com/.well-known/jwks | jq
```

> **Checkpoint:** The discovery document's `issuer` is `https://auth.oltinid.com/`, and the JWKS response contains at least one RSA key with a `kid`. The `kid` in the header of the tokens you saw in step 1 matches one of these keys.

For every field and what OneiD supports, see [Discovery document](https://oltinid.com/docs/reference/discovery/).

## Step 3: Pick a quickstart

You have seen the flow from the user's side. Next, connect your own application.

1. Decide which flow fits your application. [Choose a flow](https://oltinid.com/docs/get-started/choose-a-flow/) walks you through it.
2. Ask your OneiD administrator to register your application. [Register an application](https://oltinid.com/docs/get-started/register-an-application/) lists what to send them.
3. Follow the quickstart for your stack. The [quickstarts](https://oltinid.com/docs/quickstarts/) cover browser applications, server-side web applications, APIs and machine-to-machine calls.

> **Note:** The demonstration instance is for trying OneiD. Build your application against your own OneiD address, written in these docs as `https://YOUR_ONEID`.

## Learn more

- [How OneiD works](https://oltinid.com/docs/get-started/overview/)
- [Quickstarts](https://oltinid.com/docs/quickstarts/)
- [Discovery document](https://oltinid.com/docs/reference/discovery/)
