Playground
Try the sign-in against your own server, right here. Nothing to install: the page runs in your browser and talks to your server and to the sandbox, a stand-in for SuperPreneur with fake users.
Where /api/nonce and /api/session live. See Making your server reachable if it is on your computer.
Any route that needs a session. Checked with and without one.
Credentials: sandbox_app / sandbox_secret. Your server must use them as CLIENT_ID / CLIENT_SECRET, with this address as IDP_URL.
Runs sixteen checks: it fetches nonces, gets sandbox tokens for them, sends them to your server, and tries every bad token. A real server passes all sixteen.
The same sign-in, one request at a time, with the exact request and answer of each. Do them in order.
1. Get a nonce from your server
Your page does this first.
2. Get a token from the sandbox
In production the SuperPreneur app delivers this. Here you ask the sandbox, for the nonce from step 1.
3. Send the token and nonce to your server
Your page does this. Your server then calls the identity provider to verify.
4. Call your protected route with the session
Send any request. Pick a ready-made one, change it, and see the answer. Requests go from your browser, so the server needs to allow this page.
Paste a launch token to read it. The signature is not checked here: only the verify call can prove a token is genuine.
Making your server reachable
The playground calls your server from this page, so the browser enforces its cross-origin rule (CORS). Your server must answer in a way that allows it. If it does not, the checks report no answer even though the server is running.
- Use an address the browser can reach. A deployed HTTPS address works best. A server on your computer works at
http://localhost:PORTin Chrome, Edge and Firefox. Safari blocks plainhttpfrom an HTTPS page; use a tunnel such ascloudflared tunnel --url http://localhost:PORTorngrok http PORT, and enter the https address it prints. - Allow this page's origin. Send
Access-Control-Allow-Origin: this page's originon every/api/*answer. (Use only that origin; never*on a real server.) - Answer the preflight. The browser first sends
OPTIONSand expects204withAccess-Control-Allow-Methods: GET, POST, OPTIONSandAccess-Control-Allow-Headers: Content-Type, Authorization. - Chrome and a localhost server: if the preflight also carries
Access-Control-Request-Private-Network: true, answerAccess-Control-Allow-Private-Network: true.
Add these only while testing. The production page is served from your own origin and needs none of them.
Node.js
// at the top of your request handler
res.setHeader('Access-Control-Allow-Origin', 'ORIGIN');
res.setHeader('Access-Control-Allow-Methods', 'GET, POST, OPTIONS');
res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');
res.setHeader('Access-Control-Allow-Private-Network', 'true');
if (req.method === 'OPTIONS') { res.writeHead(204); return res.end(); }Python (http.server)
def end_headers(self): # in your request handler class
self.send_header('Access-Control-Allow-Origin', 'ORIGIN')
self.send_header('Access-Control-Allow-Methods', 'GET, POST, OPTIONS')
self.send_header('Access-Control-Allow-Headers', 'Content-Type, Authorization')
self.send_header('Access-Control-Allow-Private-Network', 'true')
super().end_headers()
def do_OPTIONS(self):
self.send_response(204)
self.end_headers()Cannot change your server? Copy the curl commands from Step by step or the API console and run them in a terminal instead. curl is not subject to CORS.