| SuperPreneur |
The mobile app users open, which hosts partner apps |
| Identity provider |
SuperPreneur's backend: it signs users in, issues launch tokens and verifies them |
| Partner app |
Your web app, opened inside SuperPreneur |
| Partner server |
Your backend: it issues nonces, verifies tokens, and keeps your sessions and data |
| Container |
The full-screen view where your page opens, under SuperPreneur's own header |
| Web shell |
A browser stand-in for the mobile app that frames your page; used for development and desktop |
| Launch token |
A signed proof, valid for 60 seconds and usable once, that a signed-in user opened your app |
| Nonce |
A one-time random string your server creates for each page load, tying a token to that load |
sub |
The user's private id in your app only; different in every app |
| Client id, client secret |
Your app's public identifier, and the password your server uses on the verify route |
| Scope |
A kind of information the user approves sharing. Today only profile (the name) |
| Consent |
The user's approval, asked once per app and revocable at any time |
| Origin |
The scheme, host and port of your launch URL; the only address allowed to talk to SuperPreneur |
| Session |
Your server's record that a page is signed in. Short-lived and held in memory |
| JWT |
The signed token format used for launch tokens: three Base64URL parts separated by dots |
| JWKS |
The identity provider's public keys, published so signatures can be checked |
| Sandbox, production |
Separate identity providers with separate credentials: one for testing, one for real users |