Identity and access
Sign in with your account in your apps
Let people sign in to a project's app with their platform account (OpenID Connect).
A project's app can let people sign in with the account they use here. It's standard OpenID Connect: any OIDC library works.
Register a client
In Cloud, open the project → Settings → Sign in with → Add client:
- Name shown at sign-in: what people see on the sign-in and consent page.
- Redirect URIs: where
id.dev.gov.vinsends people back with a code, one per line.httpsURLs, plushttp://localhostfor development. Up to 10.
You get a client ID (cli_…) and a client secret (si_cs_…). The secret is shown once; store both as environment variables of the project, for example OIDC_CLIENT_ID and OIDC_CLIENT_SECRET. New secret replaces it (the old one stops working at once); deleting the client stops sign-ins and refreshes with it at once. Each project can have 10 clients. Changes are in the audit log as oauth_client.*.
Configure your app
| Setting | Value |
|---|---|
| Issuer | https://id.dev.gov.vin |
| Discovery | https://id.dev.gov.vin/.well-known/openid-configuration |
| Authorization endpoint | https://id.dev.gov.vin/oauth/authorize |
| Token endpoint | https://id.dev.gov.vin/oauth/token (client_secret_basic or client_secret_post) |
| Userinfo endpoint | https://id.dev.gov.vin/oauth/userinfo |
| Keys | https://id.dev.gov.vin/.well-known/jwks.json (ES256) |
| Flow | Authorization code with PKCE (S256, required) |
| Scopes | openid (required), profile (name), email |
The token response holds an ID token (audience: your client ID) with sub (the user id, stable), and email/email_verified and name when you asked for those scopes; nonce is echoed. The access token (1 hour, audience: your client ID) only works at the userinfo endpoint. The refresh token lasts 30 days and is replaced on every use.
The first time someone signs in to your app, they confirm it gets their name and email address. They can remove your app on their account page under Connected apps; its refresh tokens stop working then.
Example
With openid-client:
import * as client from "openid-client"
const config = await client.discovery(new URL("https://id.dev.gov.vin"), process.env.OIDC_CLIENT_ID!, process.env.OIDC_CLIENT_SECRET!)
const verifier = client.randomPKCECodeVerifier()
const url = client.buildAuthorizationUrl(config, {
redirect_uri: "https://app.example.com/auth/callback",
scope: "openid email profile",
code_challenge: await client.calculatePKCECodeChallenge(verifier),
code_challenge_method: "S256",
})
// Redirect to `url`; on the callback:
const tokens = await client.authorizationCodeGrant(config, new URL(request.url), { pkceCodeVerifier: verifier })
const { sub, email, name } = tokens.claims()!