Konubinix' opinionated web of thoughts

OIDC Silent Authentication


OpenID Connect

The OpenID Connect protocol supports a prompt=none parameter on the authentication request that allows applications to indicate that the authorization server must not display any user interaction (such as authentication, consent, or MFA).


Use of the Implicit Flow in SPAs presents security challenges requiring explicit mitigation strategies. You can use the Authorization Code Flow with PKCE in conjunction with Silent Authentication to renew sessions in SPAs.


initiate a silent authentication request, add the prompt=none parameter when you redirect a user to the /authorize endpoint of Auth0’s authentication API


Notes linking here