Scale Intelligence■ Docs
Docs / Start here / Sign in

Sign in.

A person signs in once, on the identity provider's own page. The API gateway then checks the person's token on every call and applies the person's scope and grants.

Figure 1Sign-in flowspecified
PERSONweb app, desktop appor extensionIDENTITY PROVIDEROpenID Connectcode challengeAPI GATEWAYchecks the tokennarrows the scopeSESSIONyour scopeyour grantsevery call carries the tokenYou type the password on the identity provider's page. The app keeps the token in memory.flows forwardoutside, or not yet servedthe result
A person signs in on the identity provider's page. The API gateway checks the token on every call and narrows the scope.No page of ours asks for your password.

You sign in once, in the web app, the desktop app or the browser extension. After that, every call carries a token that the API gateway checks. You type your password on the identity provider’s own page, and no page of ours asks for it.

Sign-in flow#

  1. The app opens the identity provider’s page. The provider uses OpenID Connect.
  2. The app sends a code challenge with the request. The challenge proves that this app started the sign-in, so a page that did not ask cannot capture the token.
  3. The provider sends you back with a code. The app exchanges the code for a token and keeps the token in memory.
  4. The desktop app stores the token in the operating system’s keychain between sessions. The web app and the extension keep it for the session only.
  5. The API gateway checks the token on every call. It narrows the scope to the tenant, the brand and the strategy that the call specifies, and it applies the narrowest grant that covers the call.

Your session carries your scope and your grants. One call returns what you may do in a place.

First call#

curl -X POST https://api.scaleintelligence.co/v1/session/whoami \
  -H "Scale-Key: $SCALE_KEY" -H "Scale-Scope: tenant/<id>" \
  -H "content-type: application/json" -d '{}'
import { client } from "@scale/sdk";
const me = await client.session.whoami({});
// me.body is the caller, with the tenant and the roles by brand.

The call returns a card whose body is the caller. The body lists who you are, your tenant, your roles by brand, and the grants that apply where you are. The reference lists the session routes. The page on keys shows how to make a key that acts for you or for a service.

Password and key safety#

The apps, the extension and these pages do not ask for your password. The settings show a key once, when you make it, and no page stores it. A session ends when you sign out. In the browser, a session also ends when you close the browser.

Claims#

claimstateroute or tool
The route /v1/session/sign_in signs a person in and returns the caller as the platform knows it.target/v1/session/sign_in
The route /v1/session/my_grants returns what the caller may do in a place, after the tenant, the brand and the strategy narrow the scope.target/v1/session/my_grants