SG FAPI Connect – Singpass & Corppass (FAPI 2.0)
SG FAPI Connect adds Singpass and Corppass login to OutSystems 11 Reactive Web apps using the FAPI 2.0 security profile: Pushed Authorization Requests (PAR), DPoP, PKCE, private_key_jwt and encrypted ID tokens.
private_key_jwt
No client secret is used. The component generates and stores its own signing and encryption keys and publishes the public keys (JWKS) for the Singpass / Corppass developer portal.
SGFapiConnect
SGFapiConnect_UI
SGFapiConnect_Crypto
OIDCCustomization
OIDC_Admin
Open https://<your-environment>/SGFapiConnect/Apps and click Add app. The screen shows a setup guide and provider-specific hints. Fill in:
https://<your-environment>/SGFapiConnect/Apps
MyPortal_Singpass
.well-known/openid-configuration
openid user.identity name email mobileno
openid entity.identity entity.basic_profile.name user.identity user.name
authinfo
tpauthinfo
APP_AUTHENTICATION_DEFAULT
urn:singpass:authentication:loa:2
urn:singpass:authentication:loa:3
Click Save. The discovery URL is validated and the app's keys are generated. Use separate apps for staging and production.
Open the app's details page and copy (copy buttons provided):
https://<your-environment>/SGFapiConnect/rest/Callback/Redirect
https://<your-environment>/SGFapiConnect/rest/FAPI/JWKS?AppName=<AppName>
Register both in the Singpass / Corppass developer portal for your client.
Get_Authorization_URL
Get_UserClaims
Get_Logout_URL
Corppass_GetAuthInfo
Get_Authorization_URL(AppName: "<AppName>", OriginalURL: <page to return to>)
OriginalURL
Get_Logout_URL(OriginalURL)
Inputs: AppName, OriginalURL, AdditionalScopes (optional), ErrorURL (optional). Output: URL.Starts the FAPI 2.0 login (PAR) and returns the URL to redirect to.
Outputs: JWT_Claim (list), Success, ErrorMessage, Subject.Claims of the logged-in user. Useful keys: preferred_username, name, email, phone_number, sub, sub_type, sub_attributes.*, act.*, entity_id, entity_name.
preferred_username
name
email
phone_number
sub
sub_type
sub_attributes.*
act.*
entity_id
entity_name
Output: IdToken. Raw ID token (decrypted JWT) of the session.
Outputs: AuthToken, AutorizationHeader.DPoP-bound access token while valid. Singpass / Corppass do not issue refresh tokens; when it expires the user must sign in again.
Input: OriginalURL. Output: URL. Ends the session and returns to OriginalURL.
Inputs: AppName, UserId (optional – empty = logged-in user). Outputs: Found, AuthInfoJson, TpAuthInfoJson, CapturedOn.Corppass e-service roles captured at login (requires the authinfo / tpauthinfo scopes).
Raised when Singpass / Corppass returns HTTP 400 or above. The message contains the provider's error and error_description.
error
error_description
Implement your own user mapping and enable Custom user mapping on the app.
act.sub
iss
See the SG FAPI Connect Demo asset (SingpassDemo) for a working example. It can be tested with MockPass.
Based on the Forge OIDC Client component by OutSystems (BSD-3-Clause). Released under BSD-3-Clause.
Singpass and Corppass are trademarks of the Government of Singapore. This component is not affiliated with or endorsed by GovTech Singapore or OutSystems.