can-idLive demo

OpenID Connect, live

This app has no password system.

It never sees your password. A separate identity provider handles sign-in. That provider is the demo.

can-id is a clean-room OpenID Connect / OAuth 2.0 / SAML 2.0 identity provider: about 24,500 lines of Go written from the published specifications, backed by PostgreSQL, running live at https://auth.andrewbello.ca.

Use a throwaway email. Your account lasts 7 days, so you can come back and show someone. There is no password reset here, so pick something you will remember.

The provider's own screens are bilingual. Start the sign-in in French, which just adds the standard OIDC ui_locales=fr parameter to the authorization request. This demo app is English only; the French is coming from can-id.

You've seen this before

Same idea as "Sign in with Google", except the provider isn't Google. Nothing here is a mock: it is a real provider doing the real protocol, and this app is a real client of it.

What to watch for

You sign in on the provider's domain, then come back here. The result page shows the identity that came back and every check this app ran before trusting it.

Any app can show a name. Proving who issued it, who it's for, and that it's fresh. That's the actual work.

How safe is it?

Bank-grade math

Signatures use ECDSA P-256, the curve securing most major websites. Stored secrets are AES-256 encrypted, and passwords are hashed 600,000 times before they're stored.

Short-lived passes

Access tokens expire in 5 to 15 minutes, so a stolen one goes stale fast. Refresh tokens rotate on every use, and reusing an old one kills the whole token family.

Nothing leaves the building

Passwords are screened against billions of breached credentials without ever leaving the server. Add a second factor with an authenticator app or a passkey.

Standards implemented

OIDC Core + Discovery PKCE S256 DPoP PAR Device Grant JWT Bearer Introspection & Revocation Back-Channel Logout SAML 2.0 IdP SCIM 2.0 TOTP WebAuthn passkeys EN / FR bilingual ›

Independently checked

38 of 39 OpenID Foundation discovery-conformance assertions pass on the live provider. The one miss (RS256) is a documented design choice, not a defect. Results and rig details →