Skip to main content

Klubero SSO – Integration Guide

Welcome to the Klubero SSO integration guide. This documentation will help you integrate Klubero SSO into your applications using the standard OpenID Connect (OIDC) and OAuth 2.0 protocols.

What is Klubero SSO?​

Klubero SSO is a centralized authentication and authorization service that lets users sign in once and securely access multiple applications. It implements the OpenID Connect (OIDC) protocol built on top of OAuth 2.0 and provides:

  • Single Sign-On (SSO) – Users authenticate once and gain access to all connected applications
  • Secure token-based authentication – Standard JWT tokens for secure API access
  • Multiple authentication methods – Password, Magic Link (passwordless), external providers (Google, Facebook, Seznam.cz)
  • Two-factor authentication – An additional layer of security via an authenticator app (TOTP) or email
  • Granular permissions – Access control for API resources using scopes
  • Session management – Full visibility and control over active sessions

OpenID Connect compatibility​

Klubero SSO is fully compliant with the OpenID Connect Core 1.0 specification. You can use any standard OIDC client library for the integration. We recommend using well-maintained libraries such as:

  • JavaScript/Node.js: openid-client, oidc-client-ts
  • C# / .NET: Microsoft.AspNetCore.Authentication.OpenIdConnect
  • Python: authlib, python-jose
  • Java: Spring Security OAuth2
  • PHP: league/oauth2-client

Prerequisites​

Before you begin the integration, make sure you have:

  • HTTPS enabled in your application (required for all OAuth redirects)
  • Application credentials (client_id and optionally client_secret) from Klubero support
  • Registered redirect URIs for your application
  • An understanding of OAuth 2.0 / OIDC concepts (see the glossary below)

Glossary​

TermDefinition
Access TokenA JWT token used to authenticate API requests. Short-lived (30 minutes).
Refresh TokenA long-lived token (14 days) used to obtain new access tokens without user interaction.
ID TokenA JWT containing the user's identity information (claims) after successful authentication.
Authorization CodeA temporary code exchanged for tokens. Valid for 5 minutes, single-use.
ScopeA permission that defines which data or actions an application can access.
PKCEProof Key for Code Exchange – a security extension for public clients (SPAs, mobile apps).
Client IDThe public identifier of your application. Safe to expose in frontend code.
Client SecretYour application's secret key. Never expose it in frontend code.
Redirect URIThe URL users are redirected to after authentication. Must be registered in advance.
ConsentThe user's approval of an application's access to their data.
ClaimsInformation about the user (e.g. email, name) contained in tokens.

Support​

If you run into problems or have questions that aren't covered in this documentation, contact us at:

Email: support@klubero.cz