Skip to main content

Sign in with AISafe

An approved web app can let people use their AISafe account to sign in. The DefCamp CTF is the first such app. Players can sign up for AISafe with email, GitHub, or Google, and choose a separate public CTF handle.

The app uses OpenID Connect authorization code flow. Its operator registers the exact HTTPS callback URL and receives a client ID and secret. In production, use issuer https://api.aisafe.io and discovery URL https://api.aisafe.io/.well-known/openid-configuration. Discovery supplies the authorization, token, UserInfo, and signing-key URLs. UserInfo accepts a Bearer token on either GET or POST.

  1. Send the browser to the advertised authorization endpoint with response_type=code, client_id, the exact redirect_uri, scope=openid profile email, a random state, and PKCE S256 challenge. Store state and the PKCE verifier in the app's own short-lived session.
  2. After AISafe sign-in and consent, check state on the callback. Exchange the one-use code at the token endpoint using HTTP Basic client credentials, the original callback URL, and the PKCE verifier.
  3. Verify the ID token's RS256 signature against the JWKS, iss, aud, expiry, and nonce if sent. Fetch UserInfo with the opaque access token and require its sub to equal the ID token's sub.
  4. Key the CTF account by (issuer, sub). Treat name as display data and email as private contact data; let the player pick the public handle.

AISafe shares only account ID, name, and email, according to the requested scopes. It does not give the CTF access to AISafe projects or API keys. The player approves sharing on first use and can disconnect the app later in AISafe Settings → Connected apps. If they create an AISafe account by email, they must confirm that address, then click “Continue with AISafe” again in the CTF to start a fresh sign-in request.