Your first sign-in

Sign in to the OneiD demo application, read the discovery document of the demonstration instance and pick a quickstart.

View as Markdown

Before you connect your own application, see a OneiD sign-in from the user’s side and look at what OneiD publishes about itself. This page uses the demonstration instance that we run at https://auth.oltinid.com.

What you need

  • A web browser.
  • A terminal with curl. jq is optional and makes the JSON easier to read.
  • A demo account. Ask for one through the contact page.

Step 1: Sign in to the demo application

https://demo.oltinid.com is a small application that signs in through the demonstration instance and shows you the tokens it receives.

  1. Open https://demo.oltinid.com in your browser.
  2. Choose to sign in. The browser moves to https://auth.oltinid.com, which shows the OneiD sign-in page.
  3. Sign in with your demo account. If the account has MFA set up, enter the code from your authenticator app.
  4. If OneiD shows a consent page, review the scopes and continue.
  5. The browser returns to the demo application, which shows your tokens and their claims.

Look at the requests during step 2, for example in the network tab of your browser’s developer tools. The first request to OneiD goes to https://auth.oltinid.com/connect/authorize and carries parameters such as client_id, redirect_uri, scope, state and code_challenge. This is the authorisation request every application sends.

Checkpoint The demo application shows an ID token whose iss is https://auth.oltinid.com/, with the trailing slash, and whose sub identifies your demo account.

What to look for in the tokens

Claim Where What it tells you
iss ID token and access token Which OneiD issued the token. Ends with a slash.
sub ID token and access token The user’s stable, opaque identifier.
aud ID token The client ID of the demo application.
auth_time ID token When you signed in, in seconds since 1970.
amr ID token How you signed in, for example ["pwd"] or ["pwd","mfa"].
acr ID token The same information as one value, for example urn:oltin:ac:pwd.
scope Access token The scopes the access token carries, separated by spaces.
idp ID token and access token, with profile Where you signed in. On the demonstration instance this is local.

The access token has no aud claim. APIs check its issuer, signature, expiry and scope instead. See Tokens.

Single sign-on

After you sign in, OneiD keeps a session in your browser for 8 hours, extended while you are active. While it lasts, any other application that sends you to the same OneiD signs you in without asking for your password again.

Step 2: Read the discovery document

Every OneiD instance publishes a discovery document that lists its endpoints and capabilities. OpenID Connect libraries read it to configure themselves.

curl -s https://auth.oltinid.com/.well-known/openid-configuration | jq

The response is a JSON object. These are some of the fields you will see (abridged):

{
  "issuer": "https://auth.oltinid.com/",
  "authorization_endpoint": "https://auth.oltinid.com/connect/authorize",
  "token_endpoint": "https://auth.oltinid.com/connect/token",
  "userinfo_endpoint": "https://auth.oltinid.com/connect/userinfo",
  "end_session_endpoint": "https://auth.oltinid.com/connect/logout",
  "jwks_uri": "https://auth.oltinid.com/.well-known/jwks",
  "response_types_supported": ["code"],
  "response_modes_supported": ["form_post", "fragment", "query"],
  "grant_types_supported": ["authorization_code", "client_credentials", "refresh_token"],
  "subject_types_supported": ["public"],
  "id_token_signing_alg_values_supported": ["RS256"],
  "claims_parameter_supported": true,
  "request_parameter_supported": false,
  "request_uri_parameter_supported": false,
  "authorization_response_iss_parameter_supported": true
}

What this tells you:

  • issuer ends with a slash. Tokens carry exactly this value in iss.
  • response_types_supported is code only. Applications use the authorization code flow.
  • grant_types_supported lists the three grants OneiD supports. There is no password grant and no device flow.
  • authorization_response_iss_parameter_supported is true. OneiD adds iss to the redirect back to your application, so you can check that the response came from the OneiD you called.
  • request_parameter_supported is false. OneiD does not accept request objects.

Now fetch the public signing keys:

curl -s https://auth.oltinid.com/.well-known/jwks | jq

Checkpoint The discovery document’s issuer is https://auth.oltinid.com/, and the JWKS response contains at least one RSA key with a kid. The kid in the header of the tokens you saw in step 1 matches one of these keys.

For every field and what OneiD supports, see Discovery document.

Step 3: Pick a quickstart

You have seen the flow from the user’s side. Next, connect your own application.

  1. Decide which flow fits your application. Choose a flow walks you through it.
  2. Ask your OneiD administrator to register your application. Register an application lists what to send them.
  3. Follow the quickstart for your stack. The quickstarts cover browser applications, server-side web applications, APIs and machine-to-machine calls.

Note The demonstration instance is for trying OneiD. Build your application against your own OneiD address, written in these docs as https://YOUR_ONEID.

Learn more