We connect sign-in for your application to any OpenID Connect (OIDC) provider.

OpenID Connect is the standard behind sign-in with Google, Microsoft and most modern identity platforms. Supporting it means your application can let people sign in with the identity they already have, and your organisation can plug in its own identity provider without custom work for each one.

What we build with it

  • Single sign-on with a standards-compliant provider
  • Token-based session management
  • Claims-based role mapping

How it works

  1. The application reads the provider's published discovery document to learn its endpoints and signing keys.
  2. A user clicks sign in and is sent to the provider, which authenticates them.
  3. The provider returns a code, which the application exchanges on the server for an ID token and access token.
  4. The application checks the ID token's signature, issuer, audience and expiry, then signs the user in and maps their claims to roles.

Data exchanged

  • ID tokens containing identity claims
  • Access and refresh tokens

What is needed to set it up

  • An OIDC provider
  • Client registration with redirect URIs
  • Claim-to-role mapping

Good to know

  • The provider's signing keys rotate, and the application fetches the current keys automatically rather than storing them.
  • Mobile apps use the PKCE extension and the system browser for sign-in, which is the recommended practice for native apps.
  • Claims such as groups must be configured at the provider before the application can use them for roles.