SSO administration · prototype service · credentials are shown only once

Sign in to SSO admin

Manage relying-party clients for sso.ycvf.org. This console is restricted to authorized operators.

Need a Catholic Online account? Create one

SSO administration / Clients
issuer · sso.ycvf.org

Client registry

Register and govern the applications that may request Catholic Online sign-in.

Registered clients
0
Across prototype environments
Active clients
0
Can begin authorization
Pending review
Future workflow
Events · 24 hours
Audit persistence is future work

Relying-party clients

Exact callback and logout destinations are shown for review.

ClientEnvironmentTypeStatusLast activity
Catholic Online Web
catholic-online-web
DevelopmentConfidentialActive12 minutes ago
Test Client
test-client-ycvf
DevelopmentPublic browserDisabledYesterday

No clients registered

Register the first relying party with an exact HTTPS callback before it can start an authorization request.

Admin-only boundary. Never accept client registrations directly from an untrusted browser. Review ownership, redirect URIs, scopes, and privacy purpose before activation.

Recent activity

Administrative actions for this issuer.

  • Prototype operator registered Test ClientYesterday · exact callback review required before enabling
  • Client secret rotated for Catholic Online WebMonday · previous secret revoked

Registration checklist

Before enabling a client.

Owner and environment recorded
HTTPS callback and PKCE selected
!Consent and privacy purpose still need review

Register a client

Create a relying-party record for an application that will use Catholic Online sign-in.

Application identity

Record enough ownership context for a future audit or incident response.

Shown to users on the consent screen.Enter a client name.
Stable operator-facing key; client ID is generated separately.
Internal owner for this environment.

Client type and flow

Choose the credential boundary that matches how the application runs.

Allowed destinations

One exact URL per line. Wildcards and open return paths are rejected.

The callback must match the authorization request exactly.Use one or more exact HTTPS URLs; wildcard patterns are not allowed.
Users return here after provider logout.Use one or more exact HTTPS URLs.

Scopes and purpose

Minimize what the client can request and make the user-facing purpose explicit.

This copy appears in the consent review and should match the product privacy notice.

Client registered

The client record is ready for the next activation review.

Client registration complete

Client ID generated. Public browser clients do not receive a client secret.

One-time disclosure. Copy any generated credential now. It will not be shown again after you leave this screen.

Audit activity

A chronological view of client-registration and credential actions for the issuer.

Recent administrative events

Future implementation should make these records durable and exportable.

7 events · 24 hours
  • Registered Test ClientPrototype operator · Development · exact redirect URI recorded · Yesterday, 16:44
  • Disabled Test ClientPrototype operator · authorization blocked · Yesterday, 16:51
  • Rotated Catholic Online Web secretPrototype operator · previous secret revoked · Monday, 10:18
  • Admin session startedPrototype operator · sso.ycvf.org/admin · Today, 09:12
Audit entries should never include passwords, client secrets, authorization codes, access tokens, or ID tokens.