Introducing the new Vex ID
Vex ID is your Arioron account. It's how you sign in to VexAI, VexAPI, Classroom and arioron.com, and it's how other apps let you "Sign in with Vex ID". This release is the biggest update since launch. You can now stay signed in to several accounts at once, apps can sign you in without leaving the page, and you're properly in control of every device signed in to your account. Vex ID has also been redesigned from top to bottom in Arioron's new visual identity, and the developer platform has been rebuilt around standard OpenID Connect.
Here is what's new.
More than one account, one browser
Plenty of people have a personal account and a work account. Vex ID now lets you be signed in to both at the same time, and switch between them in a click.
- Add another account from the account menu at the bottom of the sidebar. You stay signed in to the first one.
- Switch instantly. Pick any signed-in account from the same menu and you're using it straight away, with no password prompt.
- Choose who's signing in. When an app asks you to sign in and more than one account is signed in, Vex ID shows a simple chooser first, so you decide which account the app gets.
- Sign out of one, or all. Sign out of just the account you're using and Vex ID switches you to the next one, or sign out of every account on the browser at once.
- Apps sign out only what they signed in. When an app signs you out, only that app's account leaves. Your other accounts stay put.
Sign in without leaving the page
Apps can now open Vex ID in a small popup window. You sign in, approve the app, and the window closes itself. The page you were on never reloads, so nothing you were doing is lost.
If you've used the app before and you're already signed in, the popup doesn't even ask: it opens, confirms it's you and closes in a moment.
You decide which devices stay signed in
The Sessions page now does exactly what it says.
- Signing a device out ends it. The next time that device loads a page, it's back at the sign-in screen. That includes devices that ticked "Keep me signed in".
- This device, clearly marked. The device you're using is labelled, so you never sign yourself out by accident.
- Changing your password signs out everywhere else. Resetting a forgotten password signs out every device.
- Locked accounts stay locked. If an account is disabled, it's signed out everywhere immediately.
Harder to break into
- Wrong-password limits. After ten wrong passwords, password sign-in pauses for 15 minutes. You can still sign in with a one-time email code.
- Two-factor codes have limits too. Five wrong authenticator codes and you'll need to enter your password again.
- Reset links work once. Password reset links expire after 30 minutes and stop working the moment they're used.
- Less data held. We've retired mailbox and game panel provisioning, and deleted the credentials those features stored.
A new look: Vex ID, rebuilt in the Arioron style
Vex ID now looks and feels like the rest of Arioron. Every page has been rebuilt on Arioron's new design language: ink on paper, soft edges, and nothing that shouts.
One family of pages
- The Vex ID site uses arioron.com's own layout, type and navigation, with the faint grid texture and the large, quiet headlines.
- Your account lives in the same console as VexAPI: a soft grey frame holds the sidebar, and your work sits on a raised white panel.
- Sign-in, registration and two-factor share VexAPI's sign-in layout, so signing in to any Arioron product feels the same.
A consent screen you can read at a glance
When an app asks to use your account, Vex ID now shows the app linked to your account, the site you'll go back to afterwards, the account it'll use (with a one-click switch), and a short plain-language list of exactly what it will see. Continue and Cancel sit side by side, and an app's privacy policy and terms are a click away.
Your account, at a glance
- Overview shows how your account is secured, with a single next step if something's missing, such as turning on two-factor or confirming your email.
- Security brings your password, two-factor authentication and backup codes together on one page.
- Connected apps lists every app you've signed in to and what each one can see, in plain words.
- Audit log records sign-ins, security changes and app permissions with the IP address each came from.
- Vex ecosystem links every Arioron product that your account works with.
Emails that match
Sign-in codes, password resets and email confirmations now use the same type, colours and buttons as the console, with a plain-text version for every email. Each security email tells you where the request came from, so you can spot anything unexpected.
Light and dark, everywhere
Both themes were designed side by side, and your choice carries across the Vex ID site, the console and the sign-in pages. Vex ID follows your system setting, and you can switch any time.
For developers: Sign in with Vex ID, done properly
Vex ID is a standard OAuth 2.0 and OpenID Connect provider. Point any OIDC library at the discovery document and it configures itself:
https://auth.arioron.com/oauth2/.well-known/openid-configuration
Popup sign-in and a new browser SDK
- Popup sign-in. Add
response_mode=web_messageand Vex ID hands the result back to your page, but only to your app's registered origin, instead of redirecting the popup. - Browser SDK 2.0.
signInWithPopup()andsignInWithRedirect()with PKCE built in, so single-page apps no longer need a secret. Token refresh, sign-out and a cross-tabonAuthStateChangedare included. - Server exchange. Apps with a client secret can have the SDK return the code to their backend instead.
More control over sign-in
prompt=select_accountshows the account chooser, for example behind a "Switch account" button in your app.login_hintpreselects an account by email or username.prompt=loginasks for credentials again before sensitive actions.prompt=nonechecks silently and returnslogin_requiredorconsent_requiredinstead of showing anything.- End-session with
id_token_hintsigns out only the right account and returns people to your app.
A developer console you'll actually use
- Every app gets its own page with credentials, every endpoint, and Python, Node.js and cURL quickstarts already filled in with your client ID and redirect URI.
- Webhooks for sign-ups, sign-ins and revoked tokens, now with the signing secret you need to verify them.
- Branding. Set your app's button colour on the consent screen.
- Test sign-in with one click.
Documentation, rewritten
The docs follow the same layout as VexAPI's: grouped navigation, an "On this page" outline, and syntax-highlighted code in tabs that remember your language. New guides cover popup sign-in, multiple accounts, single-page and mobile apps, server-side apps, tokens, ID token verification, signing out and errors.
Built on standards
- Authorization code flow with PKCE, refresh tokens and client credentials.
- RS256-signed ID tokens with published keys.
- Token introspection and revocation.
- Cross-origin support on the token, userinfo, revocation and discovery endpoints, so browser apps work out of the box.
- Each sign-in gets its own tokens, so signing in on a second device never signs out the first.
Get started
- Sign in at auth.arioron.com and take a look at your new Overview page.
- Turn on two-factor authentication from Security, and save your backup codes somewhere safe.
- Add a second account from the account menu and try switching.
- Building an app? Register it in the developer console and follow the quickstart in the docs.
One account, everywhere Arioron. We hope it feels that way.
The Arioron team