{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Authentication","llmstxt":{"hide":true}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"authentication","__idx":0},"children":["Authentication"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"introduction","__idx":1},"children":["Introduction"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Tidepool uses standard ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/"},"children":["OpenID Connect"]}," or ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://tools.ietf.org/html/rfc6749"},"children":["OAuth2"]}," for authentication and authorization flows. This provides a mechanism for 3rd party developers to securely request Tidepool to authenticate a user while ensuring privacy and confidentiality of that user's login credentials."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We also support external identity providers (IdP) for clinics that wish to utilize their own single sign-on (SSO) solution. Please contact ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"mailto:sales@tidepool.org"},"children":["Tidepool Sales Team"]}," to enable SSO for your clinic. Clinicians who log in to Tidepool are directed to their clinic's SSO login page that may be hosted by services such as ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.okta.com/"},"children":["Okta"]},", ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://auth0.com/"},"children":["Auth0"]},", ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://learn.microsoft.com/en-us/windows-server/identity/active-directory-federation-services"},"children":["Microsoft ADFS"]},", and so on. Upon successful login, the clinician user will be redirected back to Tidepool Web."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following references provide more detailed information on the principles and implementation of OAuth 2.0:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://openid.net/developers/how-connect-works/"},"children":["How OpenID Connect Works"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://tools.ietf.org/html/rfc6749"},"children":["OAuth - RFC 7649"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.digitalocean.com/community/tutorials/an-introduction-to-oauth-2"},"children":["An Introduction to OAuth 2"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://aaronparecki.com/2012/07/29/2/oauth2-simplified"},"children":["OAuth 2 Simplified"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.oauth.com/"},"children":["OAuth 2.0 Servers"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"access-tokens-and-refresh-tokens","__idx":2},"children":["Access Tokens and Refresh Tokens"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Tidepool access tokens are relatively short-lived (as in, minutes). Once expired, they must be refreshed using the refresh token returned by Tidepool's authentication service."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"two-factor-authentication-2fa","__idx":3},"children":["Two-Factor Authentication (2FA)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the future, Tidepool will be offering the option for users to enable 2-factor authentication (2FA) to their account to further secure their account. In order to login, the user will have to present their email and password as well as a 6-digit number generated by the 2FA provider such as 1Password or Google Authenticator."]}]},"headings":[{"value":"Authentication","id":"authentication","depth":1},{"value":"Introduction","id":"introduction","depth":2},{"value":"Access Tokens and Refresh Tokens","id":"access-tokens-and-refresh-tokens","depth":2},{"value":"Two-Factor Authentication (2FA)","id":"two-factor-authentication-2fa","depth":2}],"frontmatter":{"seo":{"title":"Authentication"}},"lastModified":"2025-07-25T15:19:47.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/authentication","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}