{"id":41957892,"url":"https://github.com/crossid/crossid-spa-js","last_synced_at":"2026-01-25T22:48:53.941Z","repository":{"id":46247118,"uuid":"382129734","full_name":"crossid/crossid-spa-js","owner":"crossid","description":"Crossid is an OAuth2 / OIDC client for single page application (SPA) with support for PKCE extension.","archived":false,"fork":false,"pushed_at":"2023-03-20T09:09:13.000Z","size":1277,"stargazers_count":3,"open_issues_count":4,"forks_count":1,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-10-19T17:46:42.670Z","etag":null,"topics":["auth","authentication","login","oauth2","oauth2-client","oidc-client","oidc-client-js","openid","openid-connect","pkce","pkce-authentication","pkce-flow","signin"],"latest_commit_sha":null,"homepage":"","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/crossid.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null}},"created_at":"2021-07-01T18:59:05.000Z","updated_at":"2025-04-15T18:01:56.000Z","dependencies_parsed_at":"2022-08-31T02:11:39.334Z","dependency_job_id":null,"html_url":"https://github.com/crossid/crossid-spa-js","commit_stats":null,"previous_names":[],"tags_count":17,"template":false,"template_full_name":null,"purl":"pkg:github/crossid/crossid-spa-js","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crossid%2Fcrossid-spa-js","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crossid%2Fcrossid-spa-js/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crossid%2Fcrossid-spa-js/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crossid%2Fcrossid-spa-js/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/crossid","download_url":"https://codeload.github.com/crossid/crossid-spa-js/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crossid%2Fcrossid-spa-js/sbom","scorecard":{"id":309551,"data":{"date":"2025-08-11","repo":{"name":"github.com/crossid/crossid-spa-js","commit":"82677e91ea389725fe9a3700837e04b8c9c9add1"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.2,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 2/29 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/publish.yml:1","Warn: no topLevel permission defined: .github/workflows/test.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/crossid/crossid-spa-js/publish.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/crossid/crossid-spa-js/publish.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/crossid/crossid-spa-js/publish.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/crossid/crossid-spa-js/test.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/crossid/crossid-spa-js/test.yml/main?enable=pin","Warn: npmCommand not pinned by hash: .github/workflows/publish.yml:18","Info:   0 out of   4 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   1 out of   2 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 3 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"18 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-78xj-cgh5-2h22","Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp","Warn: Project is vulnerable to: GHSA-593f-38f6-jp5m","Warn: Project is vulnerable to: GHSA-x2rg-q646-7m2v","Warn: Project is vulnerable to: GHSA-jgmv-j7ww-jx2x","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-gcx4-mw62-g8wm","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-76p7-773f-r4q5","Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3","Warn: Project is vulnerable to: GHSA-j8xg-fqg3-53r7","Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-17T22:54:26.491Z","repository_id":46247118,"created_at":"2025-08-17T22:54:26.491Z","updated_at":"2025-08-17T22:54:26.491Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28760955,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-25T20:56:06.009Z","status":"ssl_error","status_checked_at":"2026-01-25T20:54:48.203Z","response_time":113,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["auth","authentication","login","oauth2","oauth2-client","oidc-client","oidc-client-js","openid","openid-connect","pkce","pkce-authentication","pkce-flow","signin"],"created_at":"2026-01-25T22:48:53.867Z","updated_at":"2026-01-25T22:48:53.934Z","avatar_url":"https://github.com/crossid.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# @crossid/crossid-spa-js [![npm version](https://img.shields.io/npm/v/@crossid/crossid-spa-js?style=flat)](https://www.npmjs.com/package/@crossid/crossid-spa-js) [![Test](https://github.com/crossid/crossid-spa-js/actions/workflows/test.yml/badge.svg)](https://github.com/crossid/crossid-spa-js/actions/workflows/test.yml) [![PRs Welcome](https://img.shields.io/badge/PRs-welcome-brightgreen.svg)](https://reactjs.org/docs/how-to-contribute.html#your-first-pull-request) [![GitHub license](https://img.shields.io/badge/license-MIT-blue.svg)](https://github.com/crossid/crossid-spa-js/blob/main/LICENSE)\n\nOAuth2 and OIDC SDK for a single page application (SPA), using the authorization code flow with PKCE extension.\n\n## Get Started\n\nInstall by:\n\nnpm:\n\n```sh\nnpm install @crossid/crossid-spa-js\n```\n\nyarn:\n\n```sh\nyarn add @crossid/crossid-spa-js\n```\n\nInit a [client](https://crossid.github.io/crossid-spa-js/classes/client.html):\n\n```js\nimport { newCrossidClient, Client } from '@crossid/crossid-spa-js'\nconst crossid = newCrossidClient({\n  domain: 'acme.us.crossid.io',\n  client_id: 'my-client-id',\n  authorizationOpts: {\n    audience: ['example.com'],\n    domain: 'acme.us.crossid.io'\n    scope: 'openid profile',\n    redirect_uri: 'http://localhost:3009',\n  }\n  // use session_storage or local_storage for a persistent cache.\n  cache_type: 'memory',\n})\n```\n\nnote: the example above shows how to connect to a [crossid](https://crossid.io) tenant but this library can work with any OIDC authorization server that supports the PKCE extension. See [newCrossidClientByDiscovery](https://crossid.github.io/crossid-spa-js/modules.html#newcrossidclientbydiscovery) and [newCrossidClientCustom](https://crossid.github.io/crossid-spa-js/modules.html#newcrossidclientcustom).\n\nTo sign user in, call `crossid.loginWithRedirect({})` to redirect browser to the authprization server login page.\nThis function is typically bound to a button.\n\nOnce signing the user in completes successfully, the user will be redirected to the location specified in `redirect_uri`.\n\nAt this point, the signing in process must be completed by running the `crossid.handleLoginRedirectCallback()` function which will take care of completing the flow and caching the tokens.\n\nTo get an access token, which can be used to access your API:\n\n```js\nconst token = await client.getAccessToken()\n```\n\nTo get the authenticated user:\n\n```js\nconst user = await client.getUser()\n```\n\nFor a working example, see [example repo](https://github.com/crossid/crossid-spa-js-example).\n\n## Documentation\n\n- [Example Repo](https://github.com/crossid/crossid-spa-js-example)\n- [API Reference](https://crossid.github.io/crossid-spa-js/)\n\n## Bugs and feature requests\n\nHave a bug, feature request or feedback? Please first search for existing and closed issues. If your problem or idea is not addressed yet, [please open a new issue](https://github.com/crossid/crossid-spa-js/issues/new).\n\n## Contributing\n\nThe main purpose of this repository is to continue evolving _crossid-spa-js_, making it more secure and easier to use. Development of this library happens in the open on GitHub, and we are grateful to the community for contributing bugfixes and improvements. Read below to learn how you can take part in improving _crossid-spa-js_.\n\n## Reporting a Vulnerability\n\nThe Crossid team takes security issues very seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.\n\nTo report a security issue, email [security@crossid.io](mailto:security@crossid.io).\n\nWe'll endeavor to respond quickly, and will keep you updated throughout the process.\n\n## What is Crossid?\n\nCrossid can:\n\n- Sign users in using various _passwordless_ authentication factors (e.g., _otp_, _fingerprint_, etc...)\n- Sign users in via social providers (e,g. _Facebook_) or enterprise providers (e.g., _Azure_)\n- Multi factor authentication.\n- Issue signed OAuth2 and Openid-Connect access tokens to protect API calls.\n- Manage user profiles and access.\n\n## License\n\nThis project is licensed under the [MIT license](./LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrossid%2Fcrossid-spa-js","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcrossid%2Fcrossid-spa-js","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrossid%2Fcrossid-spa-js/lists"}