Skip to main content

Quick start

This section walks you through integrating Klubero SSO in just a few minutes.

What you'll need​

  1. Your client_id (provided by Klubero support)
  2. Your client_secret (confidential clients only)
  3. A registered redirect_uri (e.g. https://yourapp.com/callback)
  4. The base URL of your Klubero SSO (e.g. https://sso.yourdomain.com)

Step 1: Discover the configuration​

First, verify that your SSO server is reachable by fetching the OpenID configuration:

curl https://your-sso-domain.com/.well-known/openid-configuration

Response:

{
"issuer": "https://your-sso-domain.com/",
"authorization_endpoint": "https://your-sso-domain.com/connect/authorize",
"token_endpoint": "https://your-sso-domain.com/connect/token",
"userinfo_endpoint": "https://your-sso-domain.com/connect/userinfo",
"end_session_endpoint": "https://your-sso-domain.com/connect/logout",
"jwks_uri": "https://your-sso-domain.com/.well-known/jwks",
"scopes_supported": ["openid", "profile", "email", "phone", "address", "offline_access", "api"],
"response_types_supported": ["code"],
"grant_types_supported": ["authorization_code", "refresh_token", "client_credentials"],
"token_endpoint_auth_methods_supported": ["client_secret_basic", "client_secret_post"],
"code_challenge_methods_supported": ["S256", "plain"]
}

Step 2: Build the authorization URL​

Redirect the user to this URL to start authentication:

https://your-sso-domain.com/connect/authorize?
client_id=YOUR_CLIENT_ID&
redirect_uri=https://yourapp.com/callback&
response_type=code&
scope=openid%20profile%20email&
state=random_state_value

Step 3: Handle the callback​

After a successful sign-in, the user is redirected to your callback URL:

https://yourapp.com/callback?code=AUTHORIZATION_CODE&state=random_state_value

Step 4: Exchange the code for tokens​

curl -X POST https://your-sso-domain.com/connect/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code" \
-d "client_id=YOUR_CLIENT_ID" \
-d "client_secret=YOUR_CLIENT_SECRET" \
-d "code=AUTHORIZATION_CODE" \
-d "redirect_uri=https://yourapp.com/callback"

Response:

{
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6ImF0K2p3dCJ9...",
"token_type": "Bearer",
"expires_in": 1800,
"refresh_token": "R2FtY2tqZ0hkY3BXcTk4dFZ3bE5mM2xEMkNq...",
"id_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...",
"scope": "openid profile email"
}

Step 5: Retrieve user information​

curl https://your-sso-domain.com/connect/userinfo \
-H "Authorization: Bearer ACCESS_TOKEN"

Response:

{
"sub": "550e8400-e29b-41d4-a716-446655440000",
"name": "Jan Novák",
"given_name": "Jan",
"family_name": "Novák",
"email": "jan.novak@example.com",
"email_verified": true
}

Congratulations! You've successfully integrated Klubero SSO. Keep reading for detailed information about the individual flows and features.