Developer Sandbox
Integrate with the Sint Maarten eID OIDC provider using your approved sandbox client, or explore platform demo clients. Level of Assurance policy documents acr, amr, and auth_time.
- OpenID Connect 1.0
- OAuth 2.1
- PKCE S256
- Pairwise Subject ID
Step 1
Choose demo scenario
Pre-seeded government demo clients.
Password: Password123!
Step 2
Demo OIDC client
- Discovery
- https://sxm-api.orangebd.com/.well-known/openid-configuration
- Client ID
- coci-rp
- Client secret
- coci-portal-secret-2026!
- Redirect URL
- https://sxm-eid.orangebd.com/auth/callback
- Scopes
- openid profile email eid
Expected: Authorization code issued tokens returned with pairwise sub and rp_token (coci-rp + eid scope).
Relying Party Onboarding Journey
- 1Register RP application
- 2Admin Approval
- 3Retrieve credentials
- 4Run OIDC login test
- 5Pass conformance checks
- 6Request production
client registered
Client 'coci-rp' is active.
redirect uri registered
Redirect URI must match a registered value for the client.
client registered
Discovery document advertises S256 (static platform capability).
pkce s256 supported
Discovery document advertises S256 (static platform capability).
ppid pairwise sub
PPID salt configured — sub uses pairwise derivation, not raw UIN.
Integration flow
Authorization code + PKCE
1. Authorize
Redirect to /connect/authorize with PKCE.
2. Authenticate
Citizen completes MFA on the eID login page.
3. Callback
Code returned to your redirect URL.
4. Token
Exchange at /connect/token; inspect acr / amr.