OIDC DEMO APPLICATION
Welcome

Modern OIDC login for internal & external users

Sign in with Entra (internal) or Azure AD B2C (external). Role & org-based access built-in.

🔐 Sign in with Entra 🌐 Sign in with B2C

Why this demo?

Shows dual OIDC sign-in, secure session handling, CSRF protection, strict token checks, and least-privilege access.

Security Highlights

  • CSRF-protected POST routes (logout, registration)
  • Strict token checks (iss, aud, exp, iat) w/ skew
  • Session fixation defense (regeneration)
  • CSP + HSTS (toggle) + secure cookies (when HTTPS)
  • Rate limits on auth endpoints