Skip to main content

Signing in

You sign in to FossID with your organization account, through Microsoft Entra ID or Okta. There is no separate FossID password.

The sign-in window​

The Sign in to FossID window opens:

  • automatically, when the extension starts and you aren't signed in yet;
  • when you run FossID: Sign In or FossID: Set Up;
  • when you select Set Up FossID in the FossID side bar, or FossID: Not configured in the status bar;
  • when you run FossID: Reconfigure after you have signed in, to change server or account.

If you close the window without signing in, it opens again the next time the extension starts.

Server​

The Server field at the top is the address of your FossID server:

  • select Europe / US to use FossID's hosted server, https://eu1.foss.id;
  • or type your organization's own server address, for example https://fossid.example.com.

If your administrator has set the server address for you (see For administrators), it is already filled in. Whatever you enter here is saved as the setting fossid.server.url.

Important: Fill in the server before you sign in. If you sign in with the Server field empty, FossID shows Signed in. Set a FossID server URL to connect. and doesn't keep the sign-in. Enter the server address and sign in again.

Continue with Microsoft​

  1. Select Continue with Microsoft.
  2. Your browser opens at the Microsoft sign-in page. Choose your work account. Microsoft always asks which account to use, even if you are signed in to only one.
  3. When the browser page says Signed in to FossID — You can close this tab and return to VS Code., close the tab.

While you sign in, the window shows Signing in….

Continue with Okta​

  1. Select Continue with Okta. A Work email field appears.

  2. Enter your work email address (for example you@company.com), then select Continue with Okta again or press Enter.

    FossID uses the domain of your email only to find your organization's Okta sign-in. Nothing is sent until you continue. Okta may ask for your email again; that's expected.

  3. Your browser opens at your organization's Okta sign-in page. Sign in as usual.

  4. When the browser page says Signed in to FossID, close the tab.

The browser sign-in must finish within 5 minutes. During sign-in, FossID briefly listens on one of the local ports 39820, 39821 or 39822 to receive the answer from Okta. At least one of these ports must be free.

After you sign in​

The window checks the connection to your server. It shows Checking your FossID connection to <server>… and then Connected to <server>.

From this point:

  • the FossID scanner starts in the background, and files are scanned as you open and save them;
  • the status bar shows FossID, with a check mark;
  • your AI assistants are connected (see Using FossID with AI assistants).

If the connection check fails, the window explains why and offers Try again. The failures are listed under When sign-in fails.

Staying signed in​

Your FossID sign-in is short-lived by design. The extension renews it in the background before it expires, so you normally don't notice anything.

If renewal isn't possible, for example because your organization ended your session or your account lost access, the next scan fails. You then see:

  • the notification Your FossID sign-in was rejected by <server> — it may have expired, or your account may not have access. Sign in again., with a Sign In button;
  • FossID: Sign-in failed in the status bar.

Select Sign In (or the status bar item) and sign in again. The notification appears once per problem, not once per file.

Your sign-in is stored in the editor's secure storage (the operating system's keychain), never in settings or in workspace files.

Sharing your sign-in with other FossID tools​

After each sign-in and renewal, the extension also saves the current FossID sign-in to a file that other FossID tools on your machine can reuse:

PlatformLocation
macOS, Linux~/.config/fossid/credential.json (or $XDG_CONFIG_HOME/fossid/credential.json)
Windows%APPDATA%\FossID\credential.json

The file can be read only by your user account. It holds the short-lived FossID sign-in and its expiry time, but not the long-lived part used for renewal.

It works the other way round too. If you already signed in with another FossID tool and the sign-in is still valid, the extension picks it up when it starts, as long as a server address is set.

Signing out​

Run FossID: Sign Out from the Command Palette and confirm with Sign Out.

  • Your FossID sign-in is removed. The server address is kept, so signing back in doesn't require re-entering it.
  • Okta: your FossID session at Okta is also ended. Your browser may still be signed in to Okta itself. If FossID can't reach Okta to end the session, it warns you: signed out here, but your Okta session could not be ended. Sign out of Okta in your browser to end it everywhere.
  • Microsoft: your Microsoft account itself stays signed in. The extension can't end Microsoft sessions.
  • Scanning stops until you sign in again.
  • Signing out sticks. FossID doesn't sign you back in automatically until you sign in yourself.

To start over completely, run FossID: Reset Configuration. It asks for confirmation, then clears both the server address and your sign-in (ending any Okta session), and opens the sign-in window again.

Changing server​

  • FossID: Reconfigure opens the sign-in window so you can change server or account. When you change server, your existing scan results are kept where possible.
  • FossID: Set Server URL changes only the server address, from a simple input box. It doesn't check the connection; run FossID: Test Connection afterwards.

See Commands for the full list.

When sign-in fails​

The sign-in window reports problems in plain words. The most common ones:

MessageWhat it meansWhat to do
Sign-in was cancelled.You closed the browser page or cancelled at the provider.Try again.
Signed in as <you>, but your organization isn't set up for FossID yet — contact your administrator.Your Microsoft sign-in worked, but FossID has no record of your organization.Ask your administrator to set up FossID for your organization.
No Okta sign-in is configured for <address>.FossID doesn't know an Okta sign-in for your email domain.Check the email address. If your organization uses Microsoft, choose Continue with Microsoft. Otherwise contact your administrator.
Signed in as <address>, but FossID couldn't complete sign-in for your organization.Okta signed you in, but your organization's FossID setup is incomplete.Contact your administrator.
Couldn't reach FossID to find your organization's sign-in.FossID's sign-in service couldn't be reached.Check your network and try again.
<server> didn't accept your organization sign-in — it may not support SSO yet, or your account may not have access.Sign-in worked, but the server you entered doesn't accept organization sign-in, or your account has no access.Check the server address. Contact your administrator.
Enter your work email address to continue.The Work email field is empty or not an email address.Enter your full work email.
FossID: sign-in needs one of the ports 39820, 39821, 39822 and all are in use.Okta sign-in couldn't receive the browser's answer.Close the program using those ports and try again.

Connection problems that happen later, while you work, are covered in Troubleshooting.

For administrators​

Pre-set the server address. The setting fossid.server.url can be set for your developers in advance:

  • in the machine settings;
  • in workspace settings (.vscode/settings.json);
  • in a dev container configuration.

The sign-in window then opens with the address already filled in.

Microsoft Entra ID. Your Entra tenant must consent to FossID's application. It asks only for basic sign-in permissions: openid, profile, email and offline_access. You don't register an application of your own. Your organization must also be set up for FossID by FossID. Until then, users see your organization isn't set up for FossID yet.

Okta. Register an OIDC application in your own Okta organization:

  • Application type: public client (no client secret), using the authorization code flow with PKCE.
  • Grant types: Authorization Code and Refresh Token. Without Refresh Token, users can sign in but have to sign in again every time the short-lived FossID sign-in expires.
  • Sign-in redirect URIs:
    • http://127.0.0.1:39820/callback
    • http://127.0.0.1:39821/callback
    • http://127.0.0.1:39822/callback
    • the same three with localhost in place of 127.0.0.1.

Then give FossID your email domain, the Okta issuer URL and the application's client ID, so that FossID can route your users to your Okta sign-in.