ONEVAULT FOR DEVELOPERS

Less account setup.
More time for your product.

Let people bring their OneVault identity to your website or app. Ask for the information you need, explain why, and leave credentials with OneVault.

In development. Public developer enrollment and production credentials are not available yet.

ONE CONNECTION. CLEAR RESPONSIBILITIES.
01

Your application

Start a secure redirect to OneVault.

02

OneVault sign-in

The person authenticates and approves requested information.

03

Back to your product

Validate the response and create your own application session.

Your application never receives the person's OneVault password.

BUILT ON OPEN STANDARDS

A familiar protocol.
A considered experience.

The proposed integration uses OpenID Connect with the authorization code flow and PKCE. Live integration details will be available when access opens.

01

Register an application

Describe your product, ownership, privacy contact, requested information, and exact return URLs. Keep testing and production separate.

02

Use a maintained OIDC library

Validate issuer, audience, signature, expiry, state, and nonce. Identify the person by issuer and subject, never by matching email addresses.

03

Request only what you need

Explain the purpose of each profile item. A verified email indicates control of an inbox; it does not establish a person's legal identity.

04

Keep credentials private

Server applications protect their credentials on the server. Browser and mobile applications cannot safely hold a client secret.

05

Manage your connection

Use the developer section inside your OneVault account to register apps, follow authenticity reviews, manage server credentials and inspect each application's audit history.

06

Prepare for revocation

Respect withdrawn access and security events. Your application remains responsible for its sessions, roles, retained data, and deletion requests.

TRUST & CONTROL

Good for your product.
Clear for your users.

Authentication stays separate from permission

OneVault establishes who signed in. Your application decides which organizations, records, payments, and features they may access.

Oversight continues after approval

Production access will require review. Misleading consent, suspicious redirects, credential leaks, and abuse can lead to restrictions or suspension.

Connections remain a choice

People should be able to review shared information and stop future access. Disconnecting does not automatically erase data already held by your application.

BRAND & SIGN-IN BUTTON

One button.
Recognised everywhere.

Every app that offers OneVault sign-in uses the same OneVault green button with silver text, so people know exactly where they are going. Use the files unmodified and one of the approved labels: Sign in with OneVault, Continue with OneVault, or Create your OneVault ID.

Download the full-colour mark, silver mark and button styles. Use of the OneVault marks is covered by section 13 of the Developer Terms.

DEVELOPER ACCESS

Start with your account.
Build with reviewed access.

Apply as an individual or a company from your normal OneVault account. A separate developer login is not needed.

01

Describe your work

Provide your identity or company details, website, role and intended use so the review team can understand who is building the integration.

02

Verify your contacts

Verify your official email with a one-time code. Provide accurate contact details and at least one official social profile to support your application.

03

Complete authenticity review

Contact verification does not automatically approve developer access. Staff review your application before the developer workspace becomes available.

04

Register each application

Approved developers can manage multiple apps. Each app has its own review, return URLs, authorization settings and credential lifecycle. Provider activation is shown separately from approval.

Live integrations are not available yet. Developer access is subject to the Developer Terms and Acceptable Use Policy.

A LITTLE MORE DETAIL

Before you integrate.

Can every developer start using OneVault today?

Apply through Developer access in your OneVault account. Complete email verification and wait for your application decision. Live integrations are not available yet.

Will OneVault replace my application's accounts?

It replaces a repeated sign-in mechanism. You still keep an application account linked to the validated issuer and subject, plus your own permissions and business records.

Can I request access to every OneVault user?

No. An integration receives only approved information for the person who authorizes that connection. Developer access is not directory access.

What happens if my application is suspended?

The intended enforcement stops new authorizations and token issuance for the affected client. Already issued tokens and application sessions require explicit expiry or revocation handling; suspension cannot recall data already shared.