CaliplacesDevelopers
Developers - Beta

Sign in with Caliplaces

Let the calisthenics community sign in to your app with their Caliplaces account. It is plain OpenID Connect, so any certified OIDC library works out of the box.

How it works

  1. Register an app with your Caliplaces account and add the redirect URIs your app uses.
  2. Point your OIDC library at the issuer below with your client id (and secret, for web apps).
  3. Users see the Caliplaces sign-in page, sign in with Google, Apple or email, approve your app on a consent screen (only the first time), and come back to your redirect URI with an authorization code.
  4. Exchange the code for tokens and read the profile from the ID token or the UserInfo endpoint.

Endpoints

Most libraries only need the issuer and discover everything else from the discovery document.

Issuerhttps://auth.caliplaces.com
Discoveryhttps://auth.caliplaces.com/.well-known/openid-configuration
Authorizationhttps://auth.caliplaces.com/oauth/v2/authorize
Tokenhttps://auth.caliplaces.com/oauth/v2/token
UserInfohttps://auth.caliplaces.com/oidc/v1/userinfo
JWKShttps://auth.caliplaces.com/oauth/v2/keys
Revocationhttps://auth.caliplaces.com/oauth/v2/revoke
End sessionhttps://auth.caliplaces.com/oidc/v1/end_session

Pick an app type

Web

web

A server-side app (Next.js, Rails, Django, Go...). Gets a client secret, which must never reach the browser. Authenticates at the token endpoint with HTTP Basic.

Single-page app

spa

A browser-only app. Public client without a secret: the authorization code flow with PKCE (S256) is required.

Native

native

An iOS, Android or desktop app. Public client with PKCE. Redirects to a reverse-DNS custom scheme (com.example.app:/callback) or a loopback address.

Every app uses the authorization code flow with refresh tokens. The implicit flow is not available.

Scopes and claims

openidsub - the user id, unique and stable for the account
profilename, given_name, family_name, preferred_username, locale
emailemail, email_verified
offline_accessa refresh token, so your app stays signed in

These are the only scopes third-party apps may request. Any other scope, including every urn:zitadel:* scope, ends the sign-in with invalid_scope. A user who declines the consent screen comes back with access_denied.

Verification and limits

Unverified apps

Every new app starts unverified. Users see an "isn't verified by Caliplaces" warning on the consent screen, and up to 100 users can sign in.

Verify your domain

Publish a DNS TXT record on your homepage's domain from the app settings. It is checked automatically, no review. All web redirect URIs must be on that domain or its subdomains.

Names and URLs

App names can't use Caliplaces or words like official, support or login, and no URL may use a Caliplaces lookalike domain. URLs are checked against Google Web Risk.

Account limits

Your Caliplaces account must be a few days old. You can create up to 3 apps per day and have up to 10.

Reports

Users can report an app from the consent screen. Enough reports suspend it automatically until a moderator reviews it.

Quick start with Auth.js

Register a web app with the redirect URI https://your-app.com/api/auth/callback/caliplaces, then:

auth.ts
import NextAuth from 'next-auth';

export const { handlers, auth, signIn, signOut } = NextAuth({
  providers: [
    {
      id: 'caliplaces',
      name: 'Caliplaces',
      type: 'oidc',
      issuer: 'https://auth.caliplaces.com',
      clientId: process.env.CALIPLACES_CLIENT_ID,
      clientSecret: process.env.CALIPLACES_CLIENT_SECRET,
      authorization: { params: { scope: 'openid profile email' } },
      checks: ['pkce', 'state'],
    },
  ],
});

Without a library

Send the user to the authorization endpoint:

Authorization request
GET https://auth.caliplaces.com/oauth/v2/authorize
  ?client_id=YOUR_CLIENT_ID
  &redirect_uri=https%3A%2F%2Fyour-app.com%2Fcallback
  &response_type=code
  &scope=openid%20profile%20email
  &state=RANDOM_STATE
  &code_challenge=BASE64URL_SHA256_OF_VERIFIER
  &code_challenge_method=S256

Exchange the code on your server (public clients send client_id instead of Basic auth):

Token exchange
curl -X POST https://auth.caliplaces.com/oauth/v2/token \
  -u YOUR_CLIENT_ID:YOUR_CLIENT_SECRET \
  -d grant_type=authorization_code \
  -d code=THE_CODE \
  -d redirect_uri=https://your-app.com/callback \
  -d code_verifier=THE_VERIFIER

Then read the profile:

UserInfo
curl https://auth.caliplaces.com/oidc/v1/userinfo \
  -H "Authorization: Bearer ACCESS_TOKEN"

Good to know

  • Create a separate app for local development, like "My App (dev)", with your http://localhost redirect URIs, and keep localhost out of your production app.
  • Identify users by sub, never by email. Emails can change; sub does not.
  • Only trust email when email_verified is true.
  • Always send state, and a nonce when you use the ID token. Use PKCE even for web apps.
  • Redirect URIs match exactly: https on any host, http only on localhost, no wildcards.
  • Tokens issued to your app identify the user to you. They are not accepted by the Caliplaces API.
  • Keep the client secret on your server. If it leaks, rotate it from your app settings.

Branding

Label the button Sign in with Caliplaces or Continue with Caliplaces, and do not suggest that your app is made or endorsed by Caliplaces. Apps that mislead users or misuse their data are removed.

Ready to build?

Registering an app takes a minute. You can have up to 10.

Go to your apps