Skip to content
AuthMantra
Start free trial

Flow blueprint

Unified sign-in

One sign-in, three kinds of app. Open each, skip the prompt when already signed in, and try stealing the authorization code.

Simulator Unified sign-in

1 · Trigger an event

2 · Change the conditions

Ready. Pick an event.

Example event: Open the OpenID app

  1. Person browser
  2. Second factor passkey or code
  3. AuthMantra sign-in + tokens
  4. SAML 2.0 app assertion
  5. OpenID app code + PKCE
  6. Catalogue app launch tile
  7. Attacker steals the code
trace: open the openid appSimulated output
$ GET /authorize?response_type=code&code_challenge=E9Melh…&code_challenge_method=S256
session found: no prompt
302 -> app/callback?code=SplxlOBe…
$ POST /token  code_verifier=dBjftJeZ…
{"token_type":"Bearer","id_token":"eyJhbGciOi…","expires_in":3600}
✓ signature verified
  • Open the OpenID app authorization code + PKCE
  • Open the SAML app assertion to the app
  • Click a launch tile catalogue connector
  • Open a second app no new prompt
  • Revoke the session from My sessions

All output on this page is simulated, with made-up names and values. Keys 1 to 5 run the events.

What you need

Apps that speak a standard

SAML 2.0 or OpenID Connect.

The catalogue connector

Pre-built for common SaaS apps.

A second factor each

Passkey or authenticator app.

In-house apps on PKCE

Authorization code with a verifier.

A retirement list

Local passwords you can switch off.

Go deeper

Try Unified sign-in on your own people

Free for up to 10 people. Or book a consultation and we will walk through your setup.