Node.js and Express authentication starter for Tuurio ID with server-side sessions and OpenID Connect Authorization Code flow.
Generated from
Tuurio/auth_samples/auth_samples_node. Submit implementation fixes upstream so they are not replaced by the next synchronized release.
- Standards-based OpenID Connect authentication with framework-native integration.
- Exact redirect and post-logout redirect handling.
- Protected-route and logout examples.
- A reviewed, pinned Tuurio provisioning workflow.
- Create a repository with Use this template or clone this repository.
- Follow the framework-specific prerequisites below.
- Review and run this pinned provisioning command:
npx manage-tuurio-id@1.1.6 init --framework node --project-dir . --auth browser --yes --output json --campaign github_express --no-open --no-wait- Approve the exact command, then complete the secure browser handoff yourself.
- Run the build and verify one real sign-in and sign-out.
Never paste credentials, client secrets, authorization codes, tokens, session cookies, or environment-file contents into an agent chat. Browser and native applications are public clients and must not contain a client secret.
- Runtime: Node.js 20+
- Package manager: npm
- Verification:
npm ci && node --check server.js && node --check src/oauth.js
This starter uses OpenID Connect Authorization Code flow. Browser and native clients use PKCE S256 and contain no client secret. Redirect and post-logout redirect URIs must match exactly. Identity comes from the established OIDC integration or an authenticated UserInfo request; decoded JWT payloads are never treated as validation. Keep generated local environment files ignored and never commit tokens or credentials.
A server-rendered Node.js demo that signs in with OAuth 2.0 / OpenID Connect, keeps tokens server-side, and supports logout.
- Detailed integration guide: Node.js example page
- General developer docs: Tuurio ID developers
cd auth_samples_node
npm install
cp .env.example .env
# edit .env with your tenant/client values
npm startOpen http://localhost:8082.
Configure your Tuurio client with these redirect URLs (matching your .env values):
Redirect URI: http://localhost:8082/auth/callback
Post-logout Redirect URI: http://localhost:8082/logout/callback
TUURIO_ISSUER=https://YOUR_TENANT.id.tuurio.com
TUURIO_CLIENT_ID=YOUR_CLIENT_ID
TUURIO_CLIENT_SECRET=
TUURIO_REDIRECT_URI=http://localhost:8082/auth/callback
TUURIO_POST_LOGOUT_REDIRECT_URI=http://localhost:8082/logout/callback
TUURIO_SCOPE=openid profile email
TUURIO_SESSION_SECRET=tuurio-auth-sample
TUURIO_SESSION_COOKIE_NAME=tuurio.sid
TUURIO_SESSION_TRUST_PROXY=false
TUURIO_SESSION_SECURE_COOKIE=false
TUURIO_SESSION_SAME_SITE=lax
TUURIO_SESSION_MAX_AGE_MS=28800000Values come from your Tuurio Connect page:
https://<tenantId>.id.tuurio.com/admin/clients
Security notes:
- For production, set
TUURIO_SESSION_SECRETto a strong value (at least 32 chars, not default). - Behind reverse proxies, set
TUURIO_SESSION_TRUST_PROXY=true. - In production, set
TUURIO_SESSION_SECURE_COOKIE=true.
Licensed under the Apache License, Version 2.0. See LICENSE.
