Skip to main content

Organization Sign-In for Applications

With organization sign-in turned on, people sign in to your application with the account they already have in the organization that owns the project — the same one they use to sign in to the Zero console. The platform runs the sign-in, keeps the session, renews it and ends it; the application only reads who signed in:

const user = await nn.auth.user(req) // the person, or null

The application does not configure OIDC, does not keep a session, and does not receive an identity provider token, a refresh token or a secret. There is nothing to copy into variables or secrets.

Who It Is For​

  • Organization applications — dashboards, internal tools, portals — deployed as a web application with Zero's public address.
  • Anyone who needs to know who is using the application to decide what to show, without building a sign-in.

What the Application Receives​

FieldWhat it is
idthe person's identifier in the organization's IAM
username, name, email, emailVerifiedwhen the account has them
organization{ id, slug } — the project's organization
sessionIda reference to the platform session (not the cookie)

How It Works​

  1. The person opens the application. Without a session, the application decides: show the public part or send them to sign in.
  2. The sign-in happens in the organization's IAM — the usual screen, with the organization's rules (password, second factor).
  3. The platform keeps the session and, on every request, checks it and hands the application a signed identity, valid for 5 minutes and only for this application.
  4. The SDK checks the signature and returns the person.

The paths under /.nnumbers/ belong to the platform, on the application's own address:

PathWhat it does
/.nnumbers/auth/login?return_to=/dashboardsigns in and returns to the requested path (only a path of the application itself)
/.nnumbers/auth/logoutsigns out — a POST from a form of the application itself
/.nnumbers/auth/sessionthe session state, for the browser

What the Platform Guarantees​

  • The identity cannot be forged. On the way in, the platform removes any identity header coming from the browser; the identity it hands over is signed, valid for one application only and for 5 minutes. An application does not accept the identity handed to another one, nor one from another organization.
  • No credential in the application. There is no client secret; the IAM tokens stay encrypted in the platform.
  • The organization is in charge. The sign-in is the one of the project's organization — there is no way to point to another. A deactivated person or a session ended in the IAM takes down the application session when the access issued by the IAM expires, within minutes.
  • The session has limits. 30 minutes without use or 12 hours in total; signing out also ends the session in the IAM.
caution

The platform session cookie reaches the application, because the address is the same. It cannot be used to forge an identity, but do not log it or pass it on.

Limits​

  • It works on the public address Zero gives the project; custom domains do not have organization sign-in yet.
  • Web applications only.
  • Each organization needs, once, the platform to authorize application registration in its IAM. Until then the capability stays in Falta configurar na plataforma (missing platform setup), and continues on its own afterwards.
  • The console does not have the screen yet: turn it on with the CLI or the API.
  • To query organization data on behalf of the person, also turn on QueryMesh.

Next Steps​