Sign In
SSO Identity Network · All Services Operational →

Developer Hub & Documentation for SSO Develop

Central specifications, OIDC discovery, client credentials, Passkeys integration guides, developer tooling, support center, and compliance frameworks.

⌘K
⚡ Console & Keys Quotas & Limits

Enterprise OpenID Connect & OAuth 2.0 Integration

RFC 6749 / OpenID Connect Core 1.0 compliant identity provider specifications, PKCE grant flows, automated RFC 1918 private LAN redirect adaptation, free developer quotas, and microservice token validation.

Standard Identity & Discovery Endpoints

Compatible with any standard OIDC client library (NextAuth, AppAuth, oidc-client-ts, Passport).

Base: https://sso555.com
GET
Discovery Document /.well-known/openid-configuration

Standard OIDC metadata, supported scopes, response types & auth endpoints.

Test ↗
GET
JWKS Keystore /.well-known/jwks.json

Cryptographic public keys (RS256) with key rotation identifiers (kid).

Test ↗
GET
Authorization /oidc/authorize

Initiates OAuth 2.0 PKCE flow, login challenges & user consent prompt.

GET
Popup Callback /oidc/popup-callback

Lightweight HTML/JS bridge delivering auth codes to opener window via postMessage.

POST
Token Exchange /oidc/token

Exchanges authorization codes for ID tokens, access tokens & refresh tokens.

GET
User Profile & Claims /oidc/userinfo

Returns profile claims (sub, email, name, picture, role) for access tokens.

GET
Single Logout (SLO) /oidc/end_session

Terminates user session across SSO and registered client backchannels.

Automated LAN & Mobile Device Adaptation RFC 1918 Ready

Seamless local device testing on private Wi-Fi networks (iPhone, iPad, Android, testing rigs) without hardcoding IP addresses:

  • • Dynamic Host Rewriting: Redirect URLs pointing to localhost or 127.0.0.1 automatically adapt to match the incoming client host header (e.g. 192.168.1.50 or 172.20.10.4).
  • • Plain HTTP in Dev: HSTS (Strict-Transport-Security) and CSP upgrade-insecure-requests are conditioned to production only, preventing mobile browsers from enforcing invalid HTTPS upgrades on local LAN IPs.
  • • RFC 1918 / RFC 3927 Subnets: Full native support for 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and link-local 169.254.0.0/16.
Confidential Clients & Security Guardrails Zero Open-Redirects

Strict cryptographic boundaries protect users from orphaned redirect loops and authorization code leakage:

  • • Confidential Client Protection: Public self-registration is strictly blocked on confidential clients. Downstream backends require client credentials or registered secrets.
  • • Multi-Domain Session Clustering: Independent clients are isolated by default. Cross-domain SSO is permitted only within explicitly grouped clusters (SESSION_SHARING_CLUSTERS).
  • • Soft-Delete & Audit Safety: Deleted accounts and clients enter a 30-day soft-delete grace period with instant token revocation and avatar purging.

The 4 Supported Client Integration Patterns

Choose the architectural pattern that best fits your client application:

Pattern 1 Web / SSR

Full-Page Redirect

Next.js SSR, Astro SSR, Remix, PHP, Go

Standard OIDC browser redirect flow with PKCE code exchange. Handles login, consent, and session cookies securely.

sso.loginWithRedirect({ returnTo: "/dashboard" })
Pattern 2 Media / SPAs

Seamless Popup Window

Streaming players (Drama555, VaultStream), games, SPAs

Opens centered popup to /oidc/authorize?display=popup. Communicates tokens via postMessage without reloading parent page or video.

const tokens = await sso.loginWithPopup()
Pattern 3 Same-Apex SSO

Silent Session Detection

Internal subdomains sharing apex cookies (*.sso555.com)

Checks existing SSO session inside hidden iframe using prompt=none without user interaction or visual interruptions.

const session = await sso.checkSession()
Pattern 4 Daemons / APIs

Headless REST & M2M

Microservices, backend workers, client_credentials

Direct HTTP API endpoints for refreshing tokens, user claims, and daemon machine-to-machine authentication via client credentials.

const token = await sso.refreshToken()
// Initialize universal zero-dependency SSO client
import { createSsoClient } from './sso-client';

const sso = createSsoClient({
  ssoUrl: 'https://sso555.com',
  clientId: 'your-registered-client-id',
  redirectUri: 'https://your-app.com/auth/callback',
});

// Option A: Seamless Popup Login (Zero Page Reload)
const tokens = await sso.loginWithPopup();
console.log('User ID:', tokens.idTokenClaims?.sub);

// Broadcast state to open tabs via BroadcastChannel
new BroadcastChannel('sso_auth_bus').postMessage({ type: 'SSO_AUTH_SUCCESS' });

// Option B: Standard Full-Page Redirect Login
await sso.loginWithRedirect({ returnTo: '/dashboard' });
RFC 7636 PKCE S256 Handshake · Zero Dependency Universal SSO Ecosystem Standard
Security & Privacy Built-In

Designed for safety, transparency, and ease of use

Every interaction across SSO Develop is protected with industry-standard cryptographic encryption, strict origin validation, and user-first privacy controls.

Passkeys & Two-Factor Authentication

Sign in effortlessly with Face ID, Touch ID, or security keys. Phishing-resistant FIDO2 WebAuthn authentication safeguards your account without passwords.

Zero Third-Party Trackers

We respect your personal privacy. No behavioral trackers or third-party ad networks. GDPR and international data rights are fully supported by default.

Instant Self-Service Support

Access self-service account recovery guides, comprehensive FAQs, and direct escalation channels whenever you need help.