[Openid-specs-ab] SSO for native apps question

George Fletcher gffletch at aol.com
Mon Sep 18 23:12:59 UTC 2017


Hi,

I know we can use the "system browser" to achieve "SSO" on a native 
device. However, there are a number of use cases which can cause the 
user to be "logged out" or "changed" from the "system browser" perspective.

I remember a number of people discussing the use of id_tokens as a 
mechanism for applications written by the same company to share user 
authentications across native apps by bootstrapping from an id_token. I 
believe Google allows something similar on android.

Is there any official or proposed documentation for this approach? Or 
reasons this should absolutely be avoided?

I have a few ideas but I don't want to be re-inventing the wheel:)

Thanks,
George



More information about the Openid-specs-ab mailing list