Foundations track · 3 min
What happens when you sign in
Follow one sign-in from the app to AuthMantra and back.
The idea
1The app sends you away
An app using single sign-on never checks your password. It sends your browser to AuthMantra along with a one-time challenge.
2You prove who you are
AuthMantra asks for a passkey or an authenticator-app code. The app never sees either of them.
3A short-lived code comes back
Your browser returns to the app carrying a one-time authorization code. On its own, the code is worthless.
4The app trades the code for tokens
The app sends the code with its PKCE verifier and receives a signed ID token. It checks the signature.
Try it
Put one sign-in in order
Drag the steps into the order they happen, or use the arrow buttons. Then check.
This exercise needs JavaScript. Here is the answer key.
- You open the app
- The app redirects your browser to AuthMantra
- You prove who you are with a passkey or code
- Your browser returns to the app with a one-time code
- The app exchanges the code and verifier for tokens
- The app checks the signature and signs you in
Check yourself
1 of 3 Why does PKCE matter?
2 of 3 What does the app receive in the browser redirect?
3 of 3 What does the app check on the ID token?
Answer key
- Why does PKCE matter? A stolen code is useless without the verifier. Only the client that started the sign-in holds the verifier.
- What does the app receive in the browser redirect? A one-time authorization code. The code is exchanged for tokens over a back channel.
- What does the app check on the ID token? The signature, issuer and audience. These show who issued it and that it was meant for this app.
Go deeper
Field notes
Blueprints
Unified sign-inBlueprintLexicon