mikakimikaki.org

A login demo connected to the public mikaki IdP

Open the public integration demo. This application connects to the real auth.mikaki.org and only shows login state. Use a passkey already registered with mikaki. If you need an invitation, start with invitation and integration requests.

The demo requests only openid, without your name, email or Vault contents. It has no ticket or note submission. The application-specific identifier and session information needed for login are temporarily stored in a dedicated database separate from the IdP.

Sign in through the public IdP#

  1. Select “Sign in with mikaki” at https://demo.mikaki.org/?lang=en.
  2. Check that authentication is on auth.mikaki.org and the destination is demo.mikaki.org.
  3. Confirm the initial application connection and verify your registered passkey.
  4. On returning to the demo, check that “Login state” shows “Signed in”.

Registration and login are separate operations. For a new account, obtain an invitation and follow Getting started first. Read Passkeys for device and browser considerations.

Check the session again#

“Check session again” asks the public IdP about the current session from the RP server. A successful check returns to the login state page. A confirmed revocation or expiry deletes the RP session, even if an earlier confirmation period had time remaining.

Ordinary rendering uses a previous check within its validity period. A network failure does not extend that period. Reaching authentication or seeing a button alone does not prove successful code exchange or session verification.

The demo’s RP session lasts at most one hour and cannot exceed an earlier IdP expiry. Times are shown in UTC.

Sign out of this demo#

“Sign out of this demo” deletes its RP session and cookie. Check that you can no longer open the login state page. It leaves mikaki SSO active, so another login in the same browser may need fewer steps.

“Open mikaki’s sign-out confirmation” is a separate action that ends IdP SSO. Read the confirmation and consider the effect on other connected applications.

Implementation and verification scope#

The demo uses the login-only mode of the existing Helpdesk RP Worker. It has a separate HTTPS origin, D1 database and RP-specific ES256 key with an exact registered callback. Its private key stays in a Worker secret.

CheckScope
PKCE, state, nonce, ID Token signature, issuer / audienceExisting RP implementation and local integration tests
Passkey login, session checks, RP logout and rejection after revocationDemo browser test, using a disposable local OP and virtual authenticator
Public IdP client registrationDedicated public key, callback and Back-Channel receiver registered by an operator
Public passkey round trip and actual notification deliveryRequire participant actions; registration or local success alone does not establish these

The demo does not indicate OpenID Foundation certification or an independent audit. See the separate conformance results. For your own RP, read the operations and configuration and local example.