Ideapreneur Nepal logoSuperPreneur for Developers v1.0

Build an app that runs inside SuperPreneur

Your users are already signed in. This guide shows how to receive them in your own web app, with no login screen, and what to prepare before you go live.

All pages

#PageWhat it covers
1OverviewA partner app is an ordinary web app on your own server that SuperPreneur opens inside a full-screen container, already knowing who the user is. You build the app and keep your own data; SuperPreneur
2How sign-in worksYour page asks first, SuperPreneur answers with a one-time token, and your server confirms it with the identity provider. A token can only be used by the page load that asked for it.
3Browser-side contractYour page and SuperPreneur exchange three messages. Everything is JSON. SuperPreneur only answers while the page shown is served from your registered origin, so a message sent from any other site is i
4Server-side contractYour server exposes four small routes and calls one route on ours. There is no library to install: this page is the full contract, followed by an outline of the logic. Complete, tested servers in Node
5API referenceThe routes a partner server calls on the identity provider. The same information is available as an OpenAPI 3.1 file , which you can load into Postman, Insomnia or any code generator.
6Request and response examplesEvery sample below was captured from the running system and shortened only where marked. In the commands, $IDP is the identity provider's base URL, $PARTNER is your own public base URL, and $CLIENT_ID
7Generating the nonceThe nonce is a one-time random string that your server creates for every page load. It is what stops a token from being used by anyone except the page that asked for it. A good one looks like this: 8n
8Complete server examplesThese are complete, working servers. Neither uses a library or SDK: copy the one for your language and adapt it. Save each one as the file named above its code. Both pass every check in the Playground
9The sandboxThe sandbox is a hosted copy of the identity provider that holds only fake people. You use it to build and test your server before your app is registered: there is nothing to sign up for and nothing t
10Registering your appToday the SuperPreneur team registers your app for you; a self-serve console is planned. Send us the fields below and you get back a client_id and a client_secret . The secret is shown once and stored
11Security requirementsEvery partner must meet these before being set to Active. The demo apps follow all of them and are the best examples to copy.
12Going live on a public URLYour app must be reachable on the public internet, over HTTPS, at the address you registered. This page is what to prepare, and the checklist the SuperPreneur team goes through before setting your app
13Testing your appTest in three layers, from fastest to most realistic.
14Troubleshooting and open itemsAlso check: if your page looks blank inside the phone app, make sure it sets its own background and text colour. The app shows white behind your page, but a page that relies on browser defaults in dar
15Glossary

Addresses

These documents are served by the SuperPreneur identity provider itself, at /docs/ on its public address, https://superapp.ideapreneurnepal.com. Credentials for your app are issued when it is registered.