Identity and access
Sign in with your account in your apps
Let people sign in to a Serverless App Service's app with their platform account (OpenID Connect).
A Serverless App Service's app can let people sign in with the account they use here. It's standard OpenID Connect: any OIDC library works.
Register a client
In Cloud, open the Serverless App Service → Settings → Sign In With → Add Client:
- Name shown at sign-in: what people see on the sign-in and consent page.
- Redirect URIs: where
id.cactive.com.ausends people back with a code, one per line.httpsURLs, plushttp://localhostfor development. Up to 10.
You get a client ID (cli_…) and a client secret (si_cs_…). The secret is shown once; store both as environment variables of the Serverless App Service, for example OIDC_CLIENT_ID and OIDC_CLIENT_SECRET. New secret replaces it (the old one stops working at once); deleting the client stops sign-ins and refreshes with it at once. Each Serverless App Service can have 10 clients. Changes are in the audit log as oauth_client.*.
Configure your app
| Setting | Value |
|---|---|
| Issuer | https://id.cactive.com.au |
| Discovery | https://id.cactive.com.au/.well-known/openid-configuration |
| Authorization endpoint | https://id.cactive.com.au/oauth/authorize |
| Token endpoint | https://id.cactive.com.au/oauth/token (client_secret_basic or client_secret_post) |
| Userinfo endpoint | https://id.cactive.com.au/oauth/userinfo |
| Keys | https://id.cactive.com.au/.well-known/jwks.json (ES256) |
| Flow | Authorization code with PKCE (S256, required) |
| Scopes | openid (required), profile (name), email |
The token response holds an ID token (audience: your client ID) with sub (stable, and pairwise: your client gets its own identifier for each person, so two apps can't match people by it; clients added before October 2026 keep the platform's user id), and email/email_verified and name when you asked for those scopes; nonce is echoed. The access token (1 hour, audience: your client ID) only works at the userinfo endpoint. The refresh token lasts 30 days and is replaced on every use.
Set the app's website, logo URL, privacy policy and terms (https) on the client in Cloud; the sign-in page shows them with its name.
The first time someone signs in to your app, they confirm it gets their name and email address. They can remove your app on their account page under Connected apps; its refresh tokens stop working then.
Example
With openid-client:
import * as client from "openid-client"
const config = await client.discovery(new URL("https://id.cactive.com.au"), process.env.OIDC_CLIENT_ID!, process.env.OIDC_CLIENT_SECRET!)
const verifier = client.randomPKCECodeVerifier()
const url = client.buildAuthorizationUrl(config, {
redirect_uri: "https://app.example.com/auth/callback",
scope: "openid email profile",
code_challenge: await client.calculatePKCECodeChallenge(verifier),
code_challenge_method: "S256",
})
// Redirect to `url`; on the callback:
const tokens = await client.authorizationCodeGrant(config, new URL(request.url), { pkceCodeVerifier: verifier })
const { sub, email, name } = tokens.claims()!