# Register your application as a relying party

Registering an application as a relying party (RP) gives it a client ID, credentials, redirect URLs and signing permissions. After registration, use the developer portal to view the approved configuration and request changes. Keep the OpenID Connect (OIDC) client secret and the separate Secure Signature Confirmation (SSC) secret on the backend.

## 1. Register your application

On the [registration page](https://cloud.securysign.com/#/rp/register), the signed-in email becomes the RP's contact account. Enter the application name, HTTPS origin, callbacks and requested scopes. Registration is also available as a JSON request:

```bash
curl -X POST https://securysign.com/api/rp/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "clientX",
    "origin": "https://app.example.com",
    "redirect_uris": ["https://app.example.com/auth/callback"],
    "contact_email": "dev@example.com",
    "requested_scopes": ["signa:sign", "signa-kyc"]
  }'
```

| Field | Type | Required | Description |
|---|---|---|---|
| `name` | string | Yes | Your application's name, shown to your users. |
| `origin` | string | Yes | The HTTPS origin of your application. Approval authorises it as a signing origin. |
| `redirect_uris` | array of strings | Yes | Every OIDC callback URL your application uses, written exactly. |
| `contact_email` | string | Yes | The email address that owns the RP. |
| `contact_phone` | string | No | A phone number for SecurySign to reach you. |
| `logo_url` | string | No | An HTTPS URL of your logo. |
| `business_registration_number` | string | No | Your company's registration number. |
| `rate_limit_per_minute` | integer | No | You request a per-minute allowance; its registration default is `60`. |
| `requested_scopes` | array of strings | No | The scopes you need, from the [scope table](#/docs/core-concepts#scopes). You select names from the supported scope table; the granted set is confirmed after approval. |

Save the returned `rpId`, such as `42`, and `status: "pending"`. The contact email identifies the account authorized to manage the RP and register webhooks. Sign in with that account on the [RP dashboard](https://cloud.securysign.com/#/rp/dashboard). See the [registration schema](#/docs/api-relying-parties#register-rp) for the complete inputs and response.

## 2. Wait for approval

SecurySign reviews pending registrations. After approval, the dashboard displays the assigned client ID, secrets and granted scopes. The granted scopes may differ from those requested.

| Item | Example | What you use it for |
|---|---|---|
| Client ID | `signa-rp-42` | Every workflow |
| OIDC client secret | Save it at approval, because you see it once. Rotate it on the RP dashboard. | Single sign-on token exchange, identity verification |
| SSC secret | On the RP dashboard, or in `ssc_secret` from `GET /rp/me` | `POST /ssc/token` only |
| Maximum LOA | `LOA-2` | The highest level of assurance you can request in a signing token |
| Signing allowance | 60 requests per minute, 100 signatures per day, 10 documents per batch | Raise it with a [plan](#/docs/limits) |

## 3. Authorise additional signing origins

Approval authorizes the application's registered origin for iframe signing. Pass that embedding origin as `rpOrigin` in the frame URL. To add another origin, submit its exact HTTPS origin under **Authorized signing origins** on the dashboard or through `POST /rp/request-iframe-whitelist`. It becomes usable after approval; pending or unregistered origins receive `RP origin not authorized: https://other.example.com`.

## 4. Add redirect URIs

OIDC callbacks must match a registered redirect URI exactly. Choose **Request Redirect URI Change**, or call `POST /rp/request-redirect-uri-change`, with the complete replacement list. Include both new callbacks and existing callbacks that should remain active.

## 5. Enable LOA-4

Level of assurance 4 (LOA-4) binds a token to a particular signer's passkey and requires RP KYC verification and approval. Submit **Request LOA Change** for `LOA-4`, or use `POST /rp/request-loa-change`. The dashboard shows the approved maximum. Before approval, token requests may return `LOA-4 requires KYC-verified RP` or `Requested LOA LOA-4 exceeds RP maximum LOA-2`.

## 6. Manage the RP from your code

The [Relying parties API](#/docs/api-relying-parties) supports the same administration from the backend using the contact account's access token: listing RPs, reading SSC secrets, rotating the OIDC secret, requesting changes to scopes and URLs, raising the LOA, and reading allowance and usage.

## 7. Choose your workflows

Use the approved scopes and credentials for the integration needed by the application:

| You want to | Workflow | Scope |
|---|---|---|
| Sign users in with Google or your corporate directory | [Single sign-on](#/docs/sso) | `openid` for the OIDC request |
| Verify a customer's ID and face | [KYC](#/docs/kyc) | `signa-kyc` |
| Take a customer from sign-up to a signing certificate | [Enrolment](#/docs/enrolment) | `signa-enrolment` |
| Let a user sign on your page | [Iframe](#/docs/iframe) | `signa:sign` |
| Sign document hashes from your backend | [Hash signing API](#/docs/api-hash-signing) | A user access token |
| Return a signed PDF | [PAdES signing API](#/docs/api-pades-signing) | A user access token |
| Check a signature | [Verification API](#/docs/api-certificates) | Public certificate endpoints. |
| Encrypt documents to a user | [Encryption API](#/docs/api-encryption) | A user access token |

## Troubleshooting

| Error | What to do |
|---|---|
| `Unknown RP client_id` | Copy the client ID again from the RP dashboard; the registration may have been reset |
| `RP registration not approved. Status: pending` | Wait for approval |
| `Invalid client credentials` | Send the SSC secret, not the OIDC client secret |
| `RP origin not authorized: …` | Authorise the origin (step 3) |
| `Requested LOA LOA-4 exceeds RP maximum LOA-2` | Enable LOA-4 (step 5) |
| `Not authorized for this RP` | Sign in with the RP's `contact_email` |
| `Only approved RPs can be modified` | Wait for approval, then make the change |
