Skip to demo content
Step 1 of 8: One sign-in page, many identity providers
← All demos

Multi-IdP Home-Realm Discovery

1. One sign-in page, many identity providers

The app sells to many companies, and each brings its own IdP: Contoso runs Entra ID, Acme runs Okta. With no session and no realm hint, the app cannot know where to redirect -- so instead of guessing, it renders an email-first sign-in page. The routing decision comes after the user identifies themselves.

What the user sees

https://secrets.example.com/signin
Demo simulation — do not enter real credentials

Sign in to Onetime Secret

Use your work email to continue

We'll route you to your organization's sign-in page

What's happening (HTTP)

  1. REQUEST Browser → App
    GET https://secrets.example.com/signin
    Cookie: (none)
    No session cookie, no _ots_realm hint cookie from a previous visit
  2. INTERNAL App → App
    Choose sign-in mode
    No realm hint present. Render the identifier-first form instead of redirecting to any IdP.
  3. RESPONSE App → Browser
    200 OK
    Content-Type: text/html
    Cache-Control: no-store
    Email-first sign-in page rendered -- identical for every visitor, regardless of organization

Legend

Browser request
Server response
Server-to-server
Internal
← All demos
An educational demo, not a reference implementation v0.3.0