Flow blueprint
Unified sign-in
One sign-in, three kinds of app. Open each, skip the prompt when already signed in, and try stealing the authorization code.
Simulator Unified sign-in
1 · Trigger an event
2 · Change the conditions
Ready. Pick an event.
Example event: Open the OpenID app
- Person browser
- Second factor passkey or code
- AuthMantra sign-in + tokens
- SAML 2.0 app assertion
- OpenID app code + PKCE
- Catalogue app launch tile
- Attacker steals the code
$ GET /authorize?response_type=code&code_challenge=E9Melh…&code_challenge_method=S256 session found: no prompt 302 -> app/callback?code=SplxlOBe… $ POST /token code_verifier=dBjftJeZ… {"token_type":"Bearer","id_token":"eyJhbGciOi…","expires_in":3600} ✓ signature verified
- Open the OpenID app authorization code + PKCE
- Open the SAML app assertion to the app
- Click a launch tile catalogue connector
- Open a second app no new prompt
- Revoke the session from My sessions
All output on this page is simulated, with made-up names and values. Keys 1 to 5 run the events.
What you need
Apps that speak a standard
SAML 2.0 or OpenID Connect.
The catalogue connector
Pre-built for common SaaS apps.
A second factor each
Passkey or authenticator app.
In-house apps on PKCE
Authorization code with a verifier.
A retirement list
Local passwords you can switch off.
Try Unified sign-in on your own people
Free for up to 10 people. Or book a consultation and we will walk through your setup.