Gallimore Auth

One sign-in for every Gallimore app.

Gallimore Auth is the shared identity provider behind our applications. Sign in once with your Microsoft account and move between apps without signing in again.

Standard OpenID Connect

Authorization code flow with PKCE (S256), short-lived single-use codes, and RS256-signed ID tokens. Any OIDC client library works.

Microsoft Entra federation

Sign-in is federated to Microsoft Entra. We never see or store your Microsoft password.

Per-app isolation

Every app is a registered client with exact-match redirect URIs, its own audience, and its own access rules. One app's session never leaks into another.

Sessions you can end

Tokens expire in 15 minutes and every session can be revoked or signed out, from the app or here.

Who it is for

People using Gallimore apps - you will land here when an app asks you to sign in. Approve the sign-in with your Microsoft account and you return to the app.

Developers - point any standards-compliant OIDC client at https://auth.gallimoresoftware.com and follow the API docs. App registration is done in server configuration; there is no self-service signup.

A note on access

Signing in proves who you are. Whether you can use a particular app is decided by that app: each client carries its own allowlist and role requirements. If sign-in succeeds but the app says access is denied, contact the app's owner, not this service.