| "Open this app from SuperPreneur" |
You opened your page directly |
Expected. Launch it from SuperPreneur, or sign in with the Playground while building |
| "Sign-in was rejected (invalid_client)" |
Wrong client id or secret, or sandbox credentials against the hosted service (or the other way round) |
Check IDP_URL, CLIENT_ID and CLIENT_SECRET match. In the sandbox they are sandbox_app and sandbox_secret |
| "Sign-in was rejected (unknown_or_expired_nonce)" |
The server restarted, or more than 2 minutes passed between steps 1 and 5 |
Reload the page |
| "Sign-in was rejected (nonce_mismatch)" |
Your page sent a different nonce than it announced |
Send the same nonce in ready and in /api/session |
"Sign-in was rejected (replayed)" or expired |
The token was used twice, or sat for more than 60 seconds |
Use the token once, straight away |
| "Launch refused: consent_required" |
The user revoked your app |
Reopen from the launcher; the consent sheet appears again |
| "Launch refused: unknown_app" |
The app is not Active, or the client id is wrong |
Ask the SuperPreneur team to check the status |
| "SuperPreneur did not answer" |
The page's address is not your registered origin (for example a redirect to another host or port) |
Keep every page on the registered origin |
| Blank in the phone app, fine in a browser |
Plain http, which iOS and Android release builds block |
Use HTTPS |
Verify fails with a 403 and an HTML page, not JSON |
The call has no custom User-Agent, and the firewall in front of the hosted service refused it |
Send User-Agent: my-app/1.0 on the verify call |
| The Playground says "no answer" |
Your server is not running, is not on a public or reachable address, or does not allow this page's origin (CORS) |
See Making your server reachable |