Organization Sign-In for Applications
With organization sign-in turned on, people sign in to your application with the account they already have in the organization that owns the project — the same one they use to sign in to the Zero console. The platform runs the sign-in, keeps the session, renews it and ends it; the application only reads who signed in:
const user = await nn.auth.user(req) // the person, or null
The application does not configure OIDC, does not keep a session, and does not receive an identity provider token, a refresh token or a secret. There is nothing to copy into variables or secrets.
Who It Is For
- Organization applications — dashboards, internal tools, portals — deployed as a web application with Zero's public address.
- Anyone who needs to know who is using the application to decide what to show, without building a sign-in.
What the Application Receives
| Field | What it is |
|---|---|
id | the person's identifier in the organization's IAM |
username, name, email, emailVerified | when the account has them |
organization | { id, slug } — the project's organization |
sessionId | a reference to the platform session (not the cookie) |
How It Works
- The person opens the application. Without a session, the application decides: show the public part or send them to sign in.
- The sign-in happens in the organization's IAM — the usual screen, with the organization's rules (password, second factor).
- The platform keeps the session and, on every request, checks it and hands the application a signed identity, valid for 5 minutes and only for this application.
- The SDK checks the signature and returns the person.
The paths under /.nnumbers/ belong to the platform, on the application's own address:
| Path | What it does |
|---|---|
/.nnumbers/auth/login?return_to=/dashboard | signs in and returns to the requested path (only a path of the application itself) |
/.nnumbers/auth/logout | signs out — a POST from a form of the application itself |
/.nnumbers/auth/session | the session state, for the browser |
What the Platform Guarantees
- The identity cannot be forged. On the way in, the platform removes any identity header coming from the browser; the identity it hands over is signed, valid for one application only and for 5 minutes. An application does not accept the identity handed to another one, nor one from another organization.
- No credential in the application. There is no client secret; the IAM tokens stay encrypted in the platform.
- The organization is in charge. The sign-in is the one of the project's organization — there is no way to point to another. A deactivated person or a session ended in the IAM takes down the application session when the access issued by the IAM expires, within minutes.
- The session has limits. 30 minutes without use or 12 hours in total; signing out also ends the session in the IAM.
The platform session cookie reaches the application, because the address is the same. It cannot be used to forge an identity, but do not log it or pass it on.
Limits
- It works on the public address Zero gives the project; custom domains do not have organization sign-in yet.
- Web applications only.
- Each organization needs, once, the platform to authorize application registration in its IAM. Until then the capability stays in Falta configurar na plataforma (missing platform setup), and continues on its own afterwards.
- The console does not have the screen yet: turn it on with the CLI or the API.
- To query organization data on behalf of the person, also turn on QueryMesh.
Next Steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.