Klubero SSO – Integration Guide
Welcome to the Klubero SSO integration guide. This documentation will help you integrate Klubero SSO into your applications using the standard OpenID Connect (OIDC) and OAuth 2.0 protocols.
What is Klubero SSO?
Klubero SSO is a centralized authentication and authorization service that lets users sign in once and securely access multiple applications. It implements the OpenID Connect (OIDC) protocol built on top of OAuth 2.0 and provides:
- Single Sign-On (SSO) – Users authenticate once and gain access to all connected applications
- Secure token-based authentication – Standard JWT tokens for secure API access
- Multiple authentication methods – Password, Magic Link (passwordless), external providers (Google, Facebook, Seznam.cz)
- Two-factor authentication – An additional layer of security via an authenticator app (TOTP) or email
- Granular permissions – Access control for API resources using scopes
- Session management – Full visibility and control over active sessions
OpenID Connect compatibility
Klubero SSO is fully compliant with the OpenID Connect Core 1.0 specification. You can use any standard OIDC client library for the integration. We recommend using well-maintained libraries such as:
- JavaScript/Node.js:
openid-client,oidc-client-ts - C# / .NET:
Microsoft.AspNetCore.Authentication.OpenIdConnect - Python:
authlib,python-jose - Java:
Spring Security OAuth2 - PHP:
league/oauth2-client
Prerequisites
Before you begin the integration, make sure you have:
- HTTPS enabled in your application (required for all OAuth redirects)
- Application credentials (client_id and optionally client_secret) from Klubero support
- Registered redirect URIs for your application
- An understanding of OAuth 2.0 / OIDC concepts (see the glossary below)
Glossary
| Term | Definition |
|---|---|
| Access Token | A JWT token used to authenticate API requests. Short-lived (30 minutes). |
| Refresh Token | A long-lived token (14 days) used to obtain new access tokens without user interaction. |
| ID Token | A JWT containing the user's identity information (claims) after successful authentication. |
| Authorization Code | A temporary code exchanged for tokens. Valid for 5 minutes, single-use. |
| Scope | A permission that defines which data or actions an application can access. |
| PKCE | Proof Key for Code Exchange – a security extension for public clients (SPAs, mobile apps). |
| Client ID | The public identifier of your application. Safe to expose in frontend code. |
| Client Secret | Your application's secret key. Never expose it in frontend code. |
| Redirect URI | The URL users are redirected to after authentication. Must be registered in advance. |
| Consent | The user's approval of an application's access to their data. |
| Claims | Information about the user (e.g. email, name) contained in tokens. |
Support
If you run into problems or have questions that aren't covered in this documentation, contact us at:
Email: support@klubero.cz