Skip to main content

Configure a Regular Web Application

A Regular Web Application is an application that has a trusted server-side environment where authentication and sensitive credentials can be handled securely.

Use this application type for applications such as:

  • Next.js
  • Django
  • Rails
  • Laravel
  • Spring
  • Other server-rendered or backend-based applications

Quant0 uses the Authorization Code + Client Secret flow for Regular Web Applications.


When to Use a Regular Web Application​

Choose Regular web app when:

  • Your application has a backend or server-side runtime.
  • Authentication can be handled server-side.
  • Your application can securely store a client secret.
  • The browser communicates with your trusted backend.
  • Sensitive authentication credentials must remain outside the browser.

Authentication flow: Authorization Code + Client Secret


Create a Regular Web Application​

To create a Regular Web Application:

  1. Open the Quant0 Organization Portal.

  2. Navigate to Applications.

  3. Select Create application.

  4. Select Regular web app.

  5. Select Continue.


Configure Application Basics​

The Basics step allows you to configure the application's basic information.

Application Name​

Enter a name that clearly identifies your application.

Example:

My Next.js Application

Description​

The description is optional.

Example:

Server-rendered customer portal

Use the description to help administrators understand the purpose of the application.


Configure URLs​

The URLs step contains the redirect and browser-related configuration.

Allowed Callback URLs​

Configure the URL where Quant0 redirects the user after the authentication flow is completed.

Example:

https://app.example.com/callback

The callback URL must match exactly.

Important: Make sure the callback URL configured in Quant0 matches the URL used by your application.

For example, these are treated as different URLs:

https://app.example.com/callback
https://app.example.com/callback/

Allowed Web Origins​

Configure the origin used by browser requests when required.

Example:

https://app.example.com

A web origin should contain only the scheme and host.

Valid:

https://app.example.com

Invalid:

https://app.example.com/login

Sign-Out URLs​

You can optionally configure the URL where users are redirected after signing out.

Example:

https://app.example.com/signed-out

Login Entry Point​

You can optionally configure the application's login entry point.

Example:

https://app.example.com/login

Configure Sign-In and Security​

The Sign-in & security step allows you to configure the authentication options required by your application.

Password Sign-Up​

Enable this option if users should be able to register using an email address and password.

Enable this option if users should be able to authenticate using a link sent to their email address.

Require Verified Email​

Enable this option if users must verify their email address before they can sign in.


Configure Who Can Sign In​

Quant0 provides three options for controlling application access.

Open​

Anyone in the organization can sign in.

Open

Invite Only​

Only users who have been invited can sign in.

Invite only

Admin Assign​

Only users who have been assigned to the application by an administrator can sign in.

Admin assign

Choose the option that best matches your application's access requirements.


Configure Maximum Session Lifetime​

You can configure the maximum session lifetime in seconds.

Example:

3600

Alternatively, leave the setting at the organization default to use the organization's default session policy.


Review the Application​

Before creating the application, Quant0 displays a Review page.

Review the following configuration:

  • Application type
  • Application name
  • Callback URLs
  • Web origins
  • Sign-out URLs
  • Login entry point
  • Sign-in methods
  • Email verification
  • Session lifetime
  • Who can sign in
  • Application group
  • Client secret configuration

Example Configuration​

Type:
Regular web app · Authorization Code + Client Secret

Name:
My Next.js Application

Callback URL:
https://app.example.com/callback

Web origin:
https://app.example.com

Sign-in methods:
Password sign-up

Require verified email:
Yes

Who can sign in:
Open

Session lifetime:
3600 seconds

After confirming the configuration, select Create application.

After creating application go to overview