Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Foundations track · 3 min

What happens when you sign in

Follow one sign-in from the app to AuthMantra and back.

The idea

  1. 1The app sends you away

    An app using single sign-on never checks your password. It sends your browser to AuthMantra along with a one-time challenge.

  2. 2You prove who you are

    AuthMantra asks for a passkey or an authenticator-app code. The app never sees either of them.

  3. 3A short-lived code comes back

    Your browser returns to the app carrying a one-time authorization code. On its own, the code is worthless.

  4. 4The app trades the code for tokens

    The app sends the code with its PKCE verifier and receives a signed ID token. It checks the signature.

Try it

Put one sign-in in order

Drag the steps into the order they happen, or use the arrow buttons. Then check.

This exercise needs JavaScript. Here is the answer key.

  1. You open the app
  2. The app redirects your browser to AuthMantra
  3. You prove who you are with a passkey or code
  4. Your browser returns to the app with a one-time code
  5. The app exchanges the code and verifier for tokens
  6. The app checks the signature and signs you in

Check yourself

1 of 3 Why does PKCE matter?

2 of 3 What does the app receive in the browser redirect?

3 of 3 What does the app check on the ID token?

Answer key
  1. Why does PKCE matter? A stolen code is useless without the verifier. Only the client that started the sign-in holds the verifier.
  2. What does the app receive in the browser redirect? A one-time authorization code. The code is exchanged for tokens over a back channel.
  3. What does the app check on the ID token? The signature, issuer and audience. These show who issued it and that it was meant for this app.