Ideapreneur Nepal logoSuperPreneur for Developers v1.0

Playground

Try the sign-in against your own server, right here. Nothing to install: the page runs in your browser and talks to your server and to the sandbox, a stand-in for SuperPreneur with fake users.

Where /api/nonce and /api/session live. See Making your server reachable if it is on your computer.

Any route that needs a session. Checked with and without one.

Credentials: sandbox_app / sandbox_secret. Your server must use them as CLIENT_ID / CLIENT_SECRET, with this address as IDP_URL.

Runs sixteen checks: it fetches nonces, gets sandbox tokens for them, sends them to your server, and tries every bad token. A real server passes all sixteen.

    Making your server reachable

    The playground calls your server from this page, so the browser enforces its cross-origin rule (CORS). Your server must answer in a way that allows it. If it does not, the checks report no answer even though the server is running.

    1. Use an address the browser can reach. A deployed HTTPS address works best. A server on your computer works at http://localhost:PORT in Chrome, Edge and Firefox. Safari blocks plain http from an HTTPS page; use a tunnel such as cloudflared tunnel --url http://localhost:PORT or ngrok http PORT, and enter the https address it prints.
    2. Allow this page's origin. Send Access-Control-Allow-Origin: this page's origin on every /api/* answer. (Use only that origin; never * on a real server.)
    3. Answer the preflight. The browser first sends OPTIONS and expects 204 with Access-Control-Allow-Methods: GET, POST, OPTIONS and Access-Control-Allow-Headers: Content-Type, Authorization.
    4. Chrome and a localhost server: if the preflight also carries Access-Control-Request-Private-Network: true, answer Access-Control-Allow-Private-Network: true.

    Add these only while testing. The production page is served from your own origin and needs none of them.

    Node.js

    // at the top of your request handler
    res.setHeader('Access-Control-Allow-Origin', 'ORIGIN');
    res.setHeader('Access-Control-Allow-Methods', 'GET, POST, OPTIONS');
    res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization');
    res.setHeader('Access-Control-Allow-Private-Network', 'true');
    if (req.method === 'OPTIONS') { res.writeHead(204); return res.end(); }

    Python (http.server)

    def end_headers(self):                      # in your request handler class
        self.send_header('Access-Control-Allow-Origin', 'ORIGIN')
        self.send_header('Access-Control-Allow-Methods', 'GET, POST, OPTIONS')
        self.send_header('Access-Control-Allow-Headers', 'Content-Type, Authorization')
        self.send_header('Access-Control-Allow-Private-Network', 'true')
        super().end_headers()
    
    def do_OPTIONS(self):
        self.send_response(204)
        self.end_headers()

    Cannot change your server? Copy the curl commands from Step by step or the API console and run them in a terminal instead. curl is not subject to CORS.