Sign-in and registration
The ordinary OpenID Connect flow. Your application sends the user to/connect/authorize, the
sign-in window shows a QR code (or a channel button on the phone), the user confirms in the
messenger, and your application exchanges the code for tokens at /connect/token.
- Registration happens in the same action — there is no form and no password to invent.
- The result is an
id_tokenwithsub,auth_timeand the claims you asked for; the session is yours to open. - Your application stays a plain OIDC client: no Veriqa package, no SDK, only configuration.
Server-to-server transaction
A confirmation your backend asks for, with no sign-in and no browser redirect. The backend gets a token with the Client Credentials grant, creates the transaction withPOST /api/transaction/confirmation for a declared action type, shows the user the QR code or
link from the answer, and reads the outcome with GET /api/transaction/{id}/result.
- The user reads a wording declared on your host with typed slot values — “Delete ticket A-900?”, “Buy for 4.99 EUR?” — never free text from the caller.
expected_identitieslets only a given person confirm — for example the owner of the current session.- No session is created. A confirmed transaction can optionally be exchanged for the
id_tokenof the person who confirmed.
How they differ
Scenarios and their mechanism
The recipes of all sign-in scenarios are collected in
Integration scenarios.