Ideapreneur Nepal logoSuperPreneur for Developers v1.0

How sign-in works

Your page asks first, SuperPreneur answers with a one-time token, and your server confirms it with the identity provider. A token can only be used by the page load that asked for it.

A token only reaches the page load that asked for it Eight messages between the identity provider, SuperPreneur, your page and your server, in order. Identity ProviderSuperPreneurYour pageYour server 1 POST /api/nonce2 nonce, kept 2 min3 ready + nonce4 ask for token + nonce5 token, 60 s, one use6 launch message7 POST /api/session8 POST /api/launch/verify with your client secret, then your session starts
The sign-in handshake. Steps 1, 2, 7 and 8 happen on your server; step 6 is the message your page receives.
  1. Your page asks your own server for a nonce (a random one-time string).
  2. It tells SuperPreneur it is ready and sends the nonce.
  3. SuperPreneur checks the message came from your registered origin, then asks the identity provider for a token tied to that nonce. The token lasts 60 seconds and works once.
  4. SuperPreneur hands the token to your page.
  5. Your page sends the token and nonce to your server.
  6. Your server removes the nonce (so it cannot be reused), then calls the identity provider's verify route with your client secret.
  7. On success you get sub (and name if approved) and create your own session.
  8. From then on your page calls your server with that session. When it expires, the page repeats steps 1 to 7 without the user noticing.

Because of step 6, copying a link, a token or a screenshot gives an attacker nothing: the token is gone after one use or 60 seconds, and it is tied to a nonce your server issued.

What each side checks#

Who Checks
SuperPreneur The message comes from the page's registered origin, the user is signed in and has approved your app, and the app is active
Identity provider The signature, the audience (your app), the expiry, that the token is unused, that the nonce matches, and that consent still stands
Your server The nonce is one it issued, has not expired and has not been used. Then it asks the identity provider