Your first sign-in
Sign in to the OneiD demo application, read the discovery document of the demonstration instance and pick a quickstart.
Before you connect your own application, see a OneiD sign-in from the user’s side and look at what OneiD publishes about itself. This page uses the demonstration instance that we run at https://auth.oltinid.com.
What you need
- A web browser.
- A terminal with
curl.jqis optional and makes the JSON easier to read. - A demo account. Ask for one through the contact page.
Step 1: Sign in to the demo application
https://demo.oltinid.com is a small application that signs in through the demonstration instance and shows you the tokens it receives.
- Open
https://demo.oltinid.comin your browser. - Choose to sign in. The browser moves to
https://auth.oltinid.com, which shows the OneiD sign-in page. - Sign in with your demo account. If the account has MFA set up, enter the code from your authenticator app.
- If OneiD shows a consent page, review the scopes and continue.
- The browser returns to the demo application, which shows your tokens and their claims.
Look at the requests during step 2, for example in the network tab of your browser’s developer tools. The first request to OneiD goes to https://auth.oltinid.com/connect/authorize and carries parameters such as client_id, redirect_uri, scope, state and code_challenge. This is the authorisation request every application sends.
Checkpoint The demo application shows an ID token whose
issishttps://auth.oltinid.com/, with the trailing slash, and whosesubidentifies your demo account.
What to look for in the tokens
| Claim | Where | What it tells you |
|---|---|---|
iss |
ID token and access token | Which OneiD issued the token. Ends with a slash. |
sub |
ID token and access token | The user’s stable, opaque identifier. |
aud |
ID token | The client ID of the demo application. |
auth_time |
ID token | When you signed in, in seconds since 1970. |
amr |
ID token | How you signed in, for example ["pwd"] or ["pwd","mfa"]. |
acr |
ID token | The same information as one value, for example urn:oltin:ac:pwd. |
scope |
Access token | The scopes the access token carries, separated by spaces. |
idp |
ID token and access token, with profile |
Where you signed in. On the demonstration instance this is local. |
The access token has no aud claim. APIs check its issuer, signature, expiry and scope instead. See Tokens.
Single sign-on
After you sign in, OneiD keeps a session in your browser for 8 hours, extended while you are active. While it lasts, any other application that sends you to the same OneiD signs you in without asking for your password again.
Step 2: Read the discovery document
Every OneiD instance publishes a discovery document that lists its endpoints and capabilities. OpenID Connect libraries read it to configure themselves.
curl -s https://auth.oltinid.com/.well-known/openid-configuration | jq
The response is a JSON object. These are some of the fields you will see (abridged):
{
"issuer": "https://auth.oltinid.com/",
"authorization_endpoint": "https://auth.oltinid.com/connect/authorize",
"token_endpoint": "https://auth.oltinid.com/connect/token",
"userinfo_endpoint": "https://auth.oltinid.com/connect/userinfo",
"end_session_endpoint": "https://auth.oltinid.com/connect/logout",
"jwks_uri": "https://auth.oltinid.com/.well-known/jwks",
"response_types_supported": ["code"],
"response_modes_supported": ["form_post", "fragment", "query"],
"grant_types_supported": ["authorization_code", "client_credentials", "refresh_token"],
"subject_types_supported": ["public"],
"id_token_signing_alg_values_supported": ["RS256"],
"claims_parameter_supported": true,
"request_parameter_supported": false,
"request_uri_parameter_supported": false,
"authorization_response_iss_parameter_supported": true
}
What this tells you:
issuerends with a slash. Tokens carry exactly this value iniss.response_types_supportediscodeonly. Applications use the authorization code flow.grant_types_supportedlists the three grants OneiD supports. There is no password grant and no device flow.authorization_response_iss_parameter_supportedistrue. OneiD addsissto the redirect back to your application, so you can check that the response came from the OneiD you called.request_parameter_supportedisfalse. OneiD does not accept request objects.
Now fetch the public signing keys:
curl -s https://auth.oltinid.com/.well-known/jwks | jq
Checkpoint The discovery document’s
issuerishttps://auth.oltinid.com/, and the JWKS response contains at least one RSA key with akid. Thekidin the header of the tokens you saw in step 1 matches one of these keys.
For every field and what OneiD supports, see Discovery document.
Step 3: Pick a quickstart
You have seen the flow from the user’s side. Next, connect your own application.
- Decide which flow fits your application. Choose a flow walks you through it.
- Ask your OneiD administrator to register your application. Register an application lists what to send them.
- Follow the quickstart for your stack. The quickstarts cover browser applications, server-side web applications, APIs and machine-to-machine calls.
Note The demonstration instance is for trying OneiD. Build your application against your own OneiD address, written in these docs as
https://YOUR_ONEID.