# Sample RP (Python mock IdP + notes for Next / Electron)

`print_me.py --mock` starts a local mock IdP, runs PKCE S256, and prints:

```
sub= 42
rsi_handle= Yuka
```

Against sandbox (after you register a public app and complete the browser redirect):

```
python3 print_me.py --issuer https://id-dev.navcom.ai --client-id … --code … --verifier …
```

## Next.js

Use `passport-navcom` (or the authorize URL from `navcom_oauth`) on a Route Handler. Store `code_verifier` in an httpOnly cookie. Callback exchanges the code and reads `/oauth/v1/me`.

## Electron

Open the authorize URL with `shell.openExternal`. Register a custom protocol (`navcom://callback`) as the redirect URI (must also be listed on the app). PKCE S256; no embedded client secret in the asar.

First live relying party remains SENTRY-Web. Do not invent third-party RPs.
