Configure a Regular Web Application
A Regular Web Application is an application that has a trusted server-side environment where authentication and sensitive credentials can be handled securely.
Use this application type for applications such as:
- Next.js
- Django
- Rails
- Laravel
- Spring
- Other server-rendered or backend-based applications
Quant0 uses the Authorization Code + Client Secret flow for Regular Web Applications.
When to Use a Regular Web Application
Choose Regular web app when:
- Your application has a backend or server-side runtime.
- Authentication can be handled server-side.
- Your application can securely store a client secret.
- The browser communicates with your trusted backend.
- Sensitive authentication credentials must remain outside the browser.
Authentication flow: Authorization Code + Client Secret
Create a Regular Web Application
To create a Regular Web Application:
-
Open the Quant0 Organization Portal.
-
Navigate to Applications.

-
Select Create application.
-
Select Regular web app.
-
Select Continue.
Configure Application Basics
The Basics step allows you to configure the application's basic information.
Application Name
Enter a name that clearly identifies your application.
Example:
My Next.js Application
Description
The description is optional.
Example:
Server-rendered customer portal

Use the description to help administrators understand the purpose of the application.
Configure URLs
The URLs step contains the redirect and browser-related configuration.
Allowed Callback URLs
Configure the URL where Quant0 redirects the user after the authentication flow is completed.
Example:
https://app.example.com/callback
The callback URL must match exactly.
Important: Make sure the callback URL configured in Quant0 matches the URL used by your application.
For example, these are treated as different URLs:
https://app.example.com/callback
https://app.example.com/callback/
Allowed Web Origins
Configure the origin used by browser requests when required.
Example:
https://app.example.com
A web origin should contain only the scheme and host.
Valid:
https://app.example.com
Invalid:
https://app.example.com/login
Sign-Out URLs
You can optionally configure the URL where users are redirected after signing out.
Example:
https://app.example.com/signed-out
Login Entry Point
You can optionally configure the application's login entry point.
Example:
https://app.example.com/login
Configure Sign-In and Security
The Sign-in & security step allows you to configure the authentication options required by your application.
Password Sign-Up
Enable this option if users should be able to register using an email address and password.
Magic Link
Enable this option if users should be able to authenticate using a link sent to their email address.
Require Verified Email
Enable this option if users must verify their email address before they can sign in.
Configure Who Can Sign In
Quant0 provides three options for controlling application access.
Open
Anyone in the organization can sign in.
Open
Invite Only
Only users who have been invited can sign in.
Invite only
Admin Assign
Only users who have been assigned to the application by an administrator can sign in.
Admin assign
Choose the option that best matches your application's access requirements.
Configure Maximum Session Lifetime
You can configure the maximum session lifetime in seconds.
Example:
3600

Alternatively, leave the setting at the organization default to use the organization's default session policy.
Review the Application
Before creating the application, Quant0 displays a Review page.
Review the following configuration:
- Application type
- Application name
- Callback URLs
- Web origins
- Sign-out URLs
- Login entry point
- Sign-in methods
- Email verification
- Session lifetime
- Who can sign in
- Application group
- Client secret configuration
Example Configuration
Type:
Regular web app · Authorization Code + Client Secret
Name:
My Next.js Application
Callback URL:
https://app.example.com/callback
Web origin:
https://app.example.com
Sign-in methods:
Password sign-up
Require verified email:
Yes
Who can sign in:
Open
Session lifetime:
3600 seconds
After confirming the configuration, select Create application.
After creating application go to overview

