This example shows how to use the Okta React Library and React Router to login a user to a React application. The login is achieved through the PKCE Flow, where the user is redirected to the Okta-Hosted login page. After the user authenticates they are redirected back to the application with an ID token and access token.
This example is built with Create React App.
Before running this sample, you will need the following:
- The Okta CLI Tool
- An Okta Developer Account (create one using
okta register
, or configure an existing one withokta login
)
Grab and configure this project using okta start react
.
Follow the instructions printed to the console.
To run this application, install its dependencies:
npm install
With variables set, start your app:
npm start
Navigate to http://localhost:3000 in your browser.
If you see a home page that prompts you to login, then things are working! Clicking the Log in button will redirect you to the Okta hosted sign-in page.
You can sign in with the same account that you created when signing up for your Developer Org, or you can use a known username and password from your Okta Directory.
Note: If you are currently using your Developer Console, you already have a Single Sign-On (SSO) session for your Org. You will be automatically logged into your application as the same user that is using the Developer Console. You may want to use an incognito tab to test the flow from a blank slate.
If you were able to successfully login in the previous section you can continue with the resource server example. Please download and run one of these sample applications in another terminal:
- Node/Express Resource Server Example
- Java/Spring MVC Resource Server Example
- ASP.NET and ASP.NET Core Resource Server Examples
Once you have the resource server running (it will run on port 8000) you can visit the /messages
page within the React application to see the authentication flow. The React application will use its stored access token to authenticate itself with the resource server, you will see this as the Authorization: Bearer <access_token>
header on the request if you inspect the network traffic in your browser.