SG FAPI Connect Mobile adds Singpass and Corppass login to OutSystems 11 Mobile apps. It is a thin client library on top of the SG FAPI Connect web component, which does all FAPI 2.0 work on the server (PAR, DPoP, PKCE, private_key_jwt, encrypted ID token).
private_key_jwt
No keys or tokens are stored on the device. The login runs in the phone's system browser (Custom Tabs / SFSafariViewController), and the app receives only a short-lived, single-use ticket through a deep link.
SGFapi_StartLogin
AppReturnURL?ticket=…
?error=…&error_description=…
SGFapi_CompleteLogin
SGFAPIConnect_Mobile
SGFapi_Logout
SGFapiConnect
Mobile_Get_UserClaims
Mobile_Get_IdToken
Mobile_Get_AuthorizationToken
Corppass_GetAuthInfo
LoginCallback
ticket
error
error_description
SGFapi_CompleteLogin(Ticket: ticket, Error: error, ErrorDescription: error_description)
ErrorMessage
OutSystems mobile deep links have the form:
<url-scheme>://<ModuleName>/<ScreenName>
Example: myapp://MyAppModule/LoginCallback. The URL scheme is set in the app's Native Platforms settings in Service Studio (by default derived from the app name). Use exactly the same value in the next step and in every build.
myapp://MyAppModule/LoginCallback
SGFapi_StartLogin(AppName: "<AppName>", AppReturnURL: "myapp://MyAppModule/LoginCallback")
Success
Call SGFapi_Logout, then navigate to the login screen. It ends the OutSystems session on the device and clears any pending login.
Inputs: AppName, AppReturnURL, AdditionalScopes (optional). Outputs: Success, ErrorMessage.Creates the device secret, starts the FAPI 2.0 login on the server and opens the system browser.
Inputs: Ticket, Error, ErrorDescription, PersistentLogin (default True). Outputs: Success, ErrorMessage, UserId, AppName.Closes the browser, redeems the ticket and logs the user in. Provider errors arrive in Error / ErrorDescription and are returned in ErrorMessage.
Logs the user out on this device and clears any pending login.
Get_UserClaims
See SingpassDemoMobile for a working example (login, callback, home with claims, logout). It can be tested with MockPass (Singpass FAPI only).
Companion to SG FAPI Connect, which is based on the Forge OIDC Client component.
Singpass and Corppass are trademarks of the Government of Singapore. This component is not affiliated with or endorsed by GovTech Singapore or OutSystems.