Sign in with Caliplaces
Let the calisthenics community sign in to your app with their Caliplaces account. It is plain OpenID Connect, so any certified OIDC library works out of the box.
How it works
- Register an app with your Caliplaces account and add the redirect URIs your app uses.
- Point your OIDC library at the issuer below with your client id (and secret, for web apps).
- Users see the Caliplaces sign-in page, sign in with Google, Apple or email, approve your app on a consent screen (only the first time), and come back to your redirect URI with an authorization code.
- Exchange the code for tokens and read the profile from the ID token or the UserInfo endpoint.
Endpoints
Most libraries only need the issuer and discover everything else from the discovery document.
| Issuer | https://auth.caliplaces.com |
|---|---|
| Discovery | https://auth.caliplaces.com/.well-known/openid-configuration |
| Authorization | https://auth.caliplaces.com/oauth/v2/authorize |
| Token | https://auth.caliplaces.com/oauth/v2/token |
| UserInfo | https://auth.caliplaces.com/oidc/v1/userinfo |
| JWKS | https://auth.caliplaces.com/oauth/v2/keys |
| Revocation | https://auth.caliplaces.com/oauth/v2/revoke |
| End session | https://auth.caliplaces.com/oidc/v1/end_session |
Pick an app type
Web
webA server-side app (Next.js, Rails, Django, Go...). Gets a client secret, which must never reach the browser. Authenticates at the token endpoint with HTTP Basic.
Single-page app
spaA browser-only app. Public client without a secret: the authorization code flow with PKCE (S256) is required.
Native
nativeAn iOS, Android or desktop app. Public client with PKCE. Redirects to a reverse-DNS custom scheme (com.example.app:/callback) or a loopback address.
Every app uses the authorization code flow with refresh tokens. The implicit flow is not available.
Scopes and claims
| openid | sub - the user id, unique and stable for the account |
|---|---|
| profile | name, given_name, family_name, preferred_username, locale |
| email, email_verified | |
| offline_access | a refresh token, so your app stays signed in |
These are the only scopes third-party apps may request. Any other scope, including every urn:zitadel:* scope, ends the sign-in with invalid_scope. A user who declines the consent screen comes back with access_denied.
Verification and limits
Unverified apps
Every new app starts unverified. Users see an "isn't verified by Caliplaces" warning on the consent screen, and up to 100 users can sign in.
Verify your domain
Publish a DNS TXT record on your homepage's domain from the app settings. It is checked automatically, no review. All web redirect URIs must be on that domain or its subdomains.
Names and URLs
App names can't use Caliplaces or words like official, support or login, and no URL may use a Caliplaces lookalike domain. URLs are checked against Google Web Risk.
Account limits
Your Caliplaces account must be a few days old. You can create up to 3 apps per day and have up to 10.
Reports
Users can report an app from the consent screen. Enough reports suspend it automatically until a moderator reviews it.
Quick start with Auth.js
Register a web app with the redirect URI https://your-app.com/api/auth/callback/caliplaces, then:
import NextAuth from 'next-auth';
export const { handlers, auth, signIn, signOut } = NextAuth({
providers: [
{
id: 'caliplaces',
name: 'Caliplaces',
type: 'oidc',
issuer: 'https://auth.caliplaces.com',
clientId: process.env.CALIPLACES_CLIENT_ID,
clientSecret: process.env.CALIPLACES_CLIENT_SECRET,
authorization: { params: { scope: 'openid profile email' } },
checks: ['pkce', 'state'],
},
],
});Without a library
Send the user to the authorization endpoint:
GET https://auth.caliplaces.com/oauth/v2/authorize
?client_id=YOUR_CLIENT_ID
&redirect_uri=https%3A%2F%2Fyour-app.com%2Fcallback
&response_type=code
&scope=openid%20profile%20email
&state=RANDOM_STATE
&code_challenge=BASE64URL_SHA256_OF_VERIFIER
&code_challenge_method=S256Exchange the code on your server (public clients send client_id instead of Basic auth):
curl -X POST https://auth.caliplaces.com/oauth/v2/token \
-u YOUR_CLIENT_ID:YOUR_CLIENT_SECRET \
-d grant_type=authorization_code \
-d code=THE_CODE \
-d redirect_uri=https://your-app.com/callback \
-d code_verifier=THE_VERIFIERThen read the profile:
curl https://auth.caliplaces.com/oidc/v1/userinfo \
-H "Authorization: Bearer ACCESS_TOKEN"Good to know
- Create a separate app for local development, like "My App (dev)", with your http://localhost redirect URIs, and keep localhost out of your production app.
- Identify users by sub, never by email. Emails can change; sub does not.
- Only trust email when email_verified is true.
- Always send state, and a nonce when you use the ID token. Use PKCE even for web apps.
- Redirect URIs match exactly: https on any host, http only on localhost, no wildcards.
- Tokens issued to your app identify the user to you. They are not accepted by the Caliplaces API.
- Keep the client secret on your server. If it leaks, rotate it from your app settings.
Branding
Label the button Sign in with Caliplaces or Continue with Caliplaces, and do not suggest that your app is made or endorsed by Caliplaces. Apps that mislead users or misuse their data are removed.