Developer Hub & Documentation for SSO Develop
Central specifications, OIDC discovery, client credentials, Passkeys integration guides, developer tooling, support center, and compliance frameworks.
Active Ecosystem Services
Select a property to explore identity, documentation, or legal compliance.
SSO Develop Identity Provider (OIDC / OAuth2) →
Universal OpenID Connect identity provider, Passkeys / WebAuthn, OAuth 2.0 PKCE, free developer quotas, and token verification.
Help Center & Account Support →
Interactive FAQ, account recovery tutorials, security walkthroughs, mobile LAN testing, and support channels.
Legal Policies & Compliance →
Privacy Policy, Terms of Service, Cookie disclosures, User Data Deletion Instructions, and 5-locale compliance.
Developer Console & App Registration →
Self-service OAuth 2.0 / OIDC app registration, instant Client ID & Secret generation, redirect URI management, and live test sandbox.
No matching services or topics found
Try searching for "privacy", "terms", or "faq".
Enterprise OpenID Connect & OAuth 2.0 Integration
RFC 6749 / OpenID Connect Core 1.0 compliant identity provider specifications, PKCE grant flows, automated RFC 1918 private LAN redirect adaptation, free developer quotas, and microservice token validation.
Standard Identity & Discovery Endpoints
Compatible with any standard OIDC client library (NextAuth, AppAuth, oidc-client-ts, Passport).
/.well-known/openid-configuration Standard OIDC metadata, supported scopes, response types & auth endpoints.
/.well-known/jwks.json Cryptographic public keys (RS256) with key rotation identifiers (kid).
/oidc/authorize Initiates OAuth 2.0 PKCE flow, login challenges & user consent prompt.
/oidc/popup-callback Lightweight HTML/JS bridge delivering auth codes to opener window via postMessage.
/oidc/token Exchanges authorization codes for ID tokens, access tokens & refresh tokens.
/oidc/userinfo Returns profile claims (sub, email, name, picture, role) for access tokens.
/oidc/end_session Terminates user session across SSO and registered client backchannels.
Seamless local device testing on private Wi-Fi networks (iPhone, iPad, Android, testing rigs) without hardcoding IP addresses:
- • Dynamic Host Rewriting: Redirect URLs pointing to
localhostor127.0.0.1automatically adapt to match the incoming client host header (e.g.192.168.1.50or172.20.10.4). - • Plain HTTP in Dev: HSTS (
Strict-Transport-Security) and CSPupgrade-insecure-requestsare conditioned to production only, preventing mobile browsers from enforcing invalid HTTPS upgrades on local LAN IPs. - • RFC 1918 / RFC 3927 Subnets: Full native support for
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16, and link-local169.254.0.0/16.
Strict cryptographic boundaries protect users from orphaned redirect loops and authorization code leakage:
- • Confidential Client Protection: Public self-registration is strictly blocked on confidential clients. Downstream backends require client credentials or registered secrets.
- • Multi-Domain Session Clustering: Independent clients are isolated by default. Cross-domain SSO is permitted only within explicitly grouped clusters (
SESSION_SHARING_CLUSTERS). - • Soft-Delete & Audit Safety: Deleted accounts and clients enter a 30-day soft-delete grace period with instant token revocation and avatar purging.
The 4 Supported Client Integration Patterns
Choose the architectural pattern that best fits your client application:
Full-Page Redirect
Standard OIDC browser redirect flow with PKCE code exchange. Handles login, consent, and session cookies securely.
sso.loginWithRedirect({ returnTo: "/dashboard" }) Seamless Popup Window
Opens centered popup to /oidc/authorize?display=popup. Communicates tokens via postMessage without reloading parent page or video.
const tokens = await sso.loginWithPopup() Silent Session Detection
Checks existing SSO session inside hidden iframe using prompt=none without user interaction or visual interruptions.
const session = await sso.checkSession() Headless REST & M2M
Direct HTTP API endpoints for refreshing tokens, user claims, and daemon machine-to-machine authentication via client credentials.
const token = await sso.refreshToken() // Initialize universal zero-dependency SSO client
import { createSsoClient } from './sso-client';
const sso = createSsoClient({
ssoUrl: 'https://sso555.com',
clientId: 'your-registered-client-id',
redirectUri: 'https://your-app.com/auth/callback',
});
// Option A: Seamless Popup Login (Zero Page Reload)
const tokens = await sso.loginWithPopup();
console.log('User ID:', tokens.idTokenClaims?.sub);
// Broadcast state to open tabs via BroadcastChannel
new BroadcastChannel('sso_auth_bus').postMessage({ type: 'SSO_AUTH_SUCCESS' });
// Option B: Standard Full-Page Redirect Login
await sso.loginWithRedirect({ returnTo: '/dashboard' }); Designed for safety, transparency, and ease of use
Every interaction across SSO Develop is protected with industry-standard cryptographic encryption, strict origin validation, and user-first privacy controls.
Passkeys & Two-Factor Authentication
Sign in effortlessly with Face ID, Touch ID, or security keys. Phishing-resistant FIDO2 WebAuthn authentication safeguards your account without passwords.
Zero Third-Party Trackers
We respect your personal privacy. No behavioral trackers or third-party ad networks. GDPR and international data rights are fully supported by default.
Instant Self-Service Support
Access self-service account recovery guides, comprehensive FAQs, and direct escalation channels whenever you need help.