One sign-in for every Gallimore app.
Gallimore Auth is the shared identity provider behind our applications. Sign in once with your Microsoft account and move between apps without signing in again.
Standard OpenID Connect
Authorization code flow with PKCE (S256), short-lived single-use codes, and RS256-signed ID tokens. Any OIDC client library works.
Microsoft Entra federation
Sign-in is federated to Microsoft Entra. We never see or store your Microsoft password.
Per-app isolation
Every app is a registered client with exact-match redirect URIs, its own audience, and its own access rules. One app's session never leaks into another.
Sessions you can end
Tokens expire in 15 minutes and every session can be revoked or signed out, from the app or here.
Who it is for
People using Gallimore apps - you will land here when an app asks you to sign in. Approve the sign-in with your Microsoft account and you return to the app.
Developers - point any standards-compliant OIDC client at
https://auth.gallimoresoftware.com and follow the
API docs. App registration is done in server configuration; there is no
self-service signup.
A note on access
Signing in proves who you are. Whether you can use a particular app is decided by that app: each client carries its own allowlist and role requirements. If sign-in succeeds but the app says access is denied, contact the app's owner, not this service.