SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Identity and access

Sign in with your account in your apps

Let people sign in to a project's app with their platform account (OpenID Connect).

A project's app can let people sign in with the account they use here. It's standard OpenID Connect: any OIDC library works.

Register a client

In Cloud, open the project → Settings → Sign in with → Add client:

  • Name shown at sign-in: what people see on the sign-in and consent page.
  • Redirect URIs: where id.gov.vin sends people back with a code, one per line. https URLs, plus http://localhost for development. Up to 10.

You get a client ID (cli_…) and a client secret (si_cs_…). The secret is shown once; store both as environment variables of the project, for example OIDC_CLIENT_ID and OIDC_CLIENT_SECRET. New secret replaces it (the old one stops working at once); deleting the client stops sign-ins and refreshes with it at once. Each project can have 10 clients. Changes are in the audit log as oauth_client.*.

Configure your app

SettingValue
Issuerhttps://id.gov.vin
Discoveryhttps://id.gov.vin/.well-known/openid-configuration
Authorization endpointhttps://id.gov.vin/oauth/authorize
Token endpointhttps://id.gov.vin/oauth/token (client_secret_basic or client_secret_post)
Userinfo endpointhttps://id.gov.vin/oauth/userinfo
Keyshttps://id.gov.vin/.well-known/jwks.json (ES256)
FlowAuthorization code with PKCE (S256, required)
Scopesopenid (required), profile (name), email

The token response holds an ID token (audience: your client ID) with sub (the user id, stable), and email/email_verified and name when you asked for those scopes; nonce is echoed. The access token (1 hour, audience: your client ID) only works at the userinfo endpoint. The refresh token lasts 30 days and is replaced on every use.

The first time someone signs in to your app, they confirm it gets their name and email address. They can remove your app on their account page under Connected apps; its refresh tokens stop working then.

Example

With openid-client:

import * as client from "openid-client"

const config = await client.discovery(new URL("https://id.gov.vin"), process.env.OIDC_CLIENT_ID!, process.env.OIDC_CLIENT_SECRET!)
const verifier = client.randomPKCECodeVerifier()
const url = client.buildAuthorizationUrl(config, {
  redirect_uri: "https://app.example.com/auth/callback",
  scope: "openid email profile",
  code_challenge: await client.calculatePKCECodeChallenge(verifier),
  code_challenge_method: "S256",
})
// Redirect to `url`; on the callback:
const tokens = await client.authorizationCodeGrant(config, new URL(request.url), { pkceCodeVerifier: verifier })
const { sub, email, name } = tokens.claims()!