Sign in with AISafe
An approved web app can let people use their AISafe account to sign in. The DefCamp CTF is the first such app. Players can sign up for AISafe with email, GitHub, or Google, and choose a separate public CTF handle.
The app uses OpenID Connect authorization code flow. Its operator registers
the exact HTTPS callback URL and receives a client ID and secret. In
production, use issuer https://api.aisafe.io and discovery URL
https://api.aisafe.io/.well-known/openid-configuration. Discovery supplies
the authorization, token, UserInfo, and signing-key URLs.
UserInfo accepts a Bearer token on either GET or POST.
- Send the browser to the advertised authorization endpoint with
response_type=code,client_id, the exactredirect_uri,scope=openid profile email, a randomstate, and PKCES256challenge. Storestateand the PKCE verifier in the app's own short-lived session. - After AISafe sign-in and consent, check
stateon the callback. Exchange the one-use code at the token endpoint using HTTP Basic client credentials, the original callback URL, and the PKCE verifier. - Verify the ID token's RS256 signature against the JWKS,
iss,aud, expiry, andnonceif sent. Fetch UserInfo with the opaque access token and require itssubto equal the ID token'ssub. - Key the CTF account by
(issuer, sub). Treatnameas display data andemailas private contact data; let the player pick the public handle.
AISafe shares only account ID, name, and email, according to the requested scopes. It does not give the CTF access to AISafe projects or API keys. The player approves sharing on first use and can disconnect the app later in AISafe Settings → Connected apps. If they create an AISafe account by email, they must confirm that address, then click “Continue with AISafe” again in the CTF to start a fresh sign-in request.