[{"data":1,"prerenderedAt":177},["ShallowReactive",2],{"docs:index:docs_en":3,"docs:pages:docs_en":110},{"id":4,"title":5,"alt":6,"body":7,"description":99,"extension":100,"key":101,"meta":102,"navigation":103,"order":104,"path":105,"placeholder":106,"seo":107,"stem":108,"__hash__":109},"docs_en\u002Fen\u002Fdocs\u002Findex.md","Kleora documentation","\u002Fpl\u002Fdocs",{"type":8,"value":9,"toc":92},"minimark",[10,14,26,31,54,58,89],[11,12,13],"p",{},"Kleora gives your application a sign-in page you do not have to build, and an\naccess token your API can verify on its own. You create an App in the console,\npoint one of our SDKs at it, and your users sign in on a page hosted on that\nApp's own address — branded by you, with email and password, TOTP codes and, on\nPro, passkeys.",[11,15,16,17,21,22,25],{},"Every App comes with two environments, ",[18,19,20],"strong",{},"sandbox"," and ",[18,23,24],{},"production",", each with\nits own users, its own signing keys and its own address. Nothing you try in\nsandbox can reach anybody real.",[27,28,30],"h2",{"id":29},"start-here","Start here",[32,33,34,45],"ul",{},[35,36,37,44],"li",{},[18,38,39],{},[40,41,43],"a",{"href":42},"\u002Fen\u002Fdocs\u002Fgetting-started\u002Fquickstart","Quickstart"," — from an empty project\nto a working sign-in.",[35,46,47,53],{},[18,48,49],{},[40,50,52],{"href":51},"\u002Fen\u002Fdocs\u002Fgetting-started\u002Finstallation","Installing an SDK"," — the five\npackages we publish, and what each one is for.",[27,55,57],{"id":56},"what-you-get","What you get",[32,59,60,66,77,83],{},[35,61,62,65],{},[18,63,64],{},"Hosted sign-in."," Sign-in, sign-up, email verification, password reset, MFA\nand workspace selection are pages we host and you brand. Your application\nnever sees a password.",[35,67,68,71,72,76],{},[18,69,70],{},"Standard OAuth 2.1 and OpenID Connect."," Authorization code with PKCE,\ndiscovery, JWKS, rotating refresh tokens, and the device grant for terminal\ntools and agents. Everything is published at\n",[73,74,75],"code",{},"{issuer}\u002F.well-known\u002Fopenid-configuration",", so a generic OIDC client works\njust as well as one of ours.",[35,78,79,82],{},[18,80,81],{},"Workspaces and roles."," Workspaces, invitations and roles scoped to one\nworkspace. Roles and permissions ride in the access token, so your API reads\nthem from the token instead of asking us.",[35,84,85,88],{},[18,86,87],{},"A management API."," Everything the console does, your own code can do:\nusers, workspaces, clients, roles, API keys and the audit log.",[11,90,91],{},"The free plan includes 10,000 monthly active users pooled across every App in\nyour account. Passkeys and a required MFA policy are on Pro and above.",{"title":93,"searchDepth":94,"depth":94,"links":95},"",3,[96,98],{"id":29,"depth":97,"text":30},2,{"id":56,"depth":97,"text":57},"Add hosted sign-in to your application, verify the token on your API, and manage users, workspaces and roles from one console.","md","index",{},true,0,"\u002Fen\u002Fdocs",false,{"title":5,"description":99},"en\u002Fdocs\u002Findex","5fvxeLLDBks6XiuRvhq7IKVCLPXvG_10yO8JkgM3t-8",[111,117,121,124,130,135,140,145,151,156,161,166,167,172],{"path":112,"title":113,"description":114,"order":115,"key":116},"\u002Fen\u002Fdocs\u002Fgetting-started","Getting started","From an empty project to a working sign-in, and the packages that get you there.",10,"getting-started\u002Findex",{"path":51,"title":52,"description":118,"order":119,"key":120},"The five packages we publish, what each one is for, and the configuration each one takes.",20,"getting-started\u002Finstallation",{"path":42,"title":43,"description":122,"order":115,"key":123},"Create an App, wire up the browser SDK, and sign in for the first time — entirely in sandbox.","getting-started\u002Fquickstart",{"path":125,"title":126,"description":127,"order":128,"key":129},"\u002Fen\u002Fdocs\u002Fguides\u002Farchitecture","How Kleora is put together","The shape of the hosted service — one address per environment, two API surfaces, and where state lives. And why self-hosting is not something we support today.",30,"guides\u002Farchitecture",{"path":131,"title":132,"description":133,"order":119,"key":134},"\u002Fen\u002Fdocs\u002Fguides\u002Fconcepts","Workspaces, roles and environments","The five words the product is built from, which of them your tokens carry, and how a change to a role reaches a running application.","guides\u002Fconcepts",{"path":136,"title":137,"description":138,"order":119,"key":139},"\u002Fen\u002Fdocs\u002Fguides","Guides","Wiring Kleora into your stack, the words the product uses, and how the hosted service is put together.","guides\u002Findex",{"path":141,"title":142,"description":143,"order":115,"key":144},"\u002Fen\u002Fdocs\u002Fguides\u002Fquickstarts\u002Fbrowser","Plain browser","One client instance, one callback route, and an access token for every request your application makes.","guides\u002Fquickstarts\u002Fbrowser",{"path":146,"title":147,"description":148,"order":149,"key":150},"\u002Fen\u002Fdocs\u002Fguides\u002Fquickstarts\u002Fexpress","Express","Verifying the access token on your own API — middleware, permissions, and the three answers a refusal can have.",40,"guides\u002Fquickstarts\u002Fexpress",{"path":152,"title":153,"description":154,"order":115,"key":155},"\u002Fen\u002Fdocs\u002Fguides\u002Fquickstarts","Framework quickstarts","One page per stack — Next.js, Nuxt, Express and the plain browser — and the two redirect URIs all of them share.","guides\u002Fquickstarts\u002Findex",{"path":157,"title":158,"description":159,"order":119,"key":160},"\u002Fen\u002Fdocs\u002Fguides\u002Fquickstarts\u002Fnextjs","Next.js","The browser SDK in an App Router application — a lazy client, a callback route, and token verification in a route handler.","guides\u002Fquickstarts\u002Fnextjs",{"path":162,"title":163,"description":164,"order":128,"key":165},"\u002Fen\u002Fdocs\u002Fguides\u002Fquickstarts\u002Fnuxt","Nuxt","The Nuxt module — two lines of config, a callback page you do not write, and a route middleware that protects a page from its own meta.","guides\u002Fquickstarts\u002Fnuxt",{"path":105,"title":5,"description":99,"order":104,"key":101},{"path":168,"title":169,"description":170,"order":115,"key":171},"\u002Fen\u002Fdocs\u002Freference\u002Fcode-highlighting","Code highlighting","One fence per preloaded Shiki grammar — a fixture, not a reference page.","reference\u002Fcode-highlighting",{"path":173,"title":174,"description":175,"order":128,"key":176},"\u002Fen\u002Fdocs\u002Freference","Reference","Reference material for the HTTP APIs and the SDK packages.","reference\u002Findex",1790698196299]