Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Configure allowedRedirectUris in rayfin/rayfin.yml for authentication callbacks and the Fabric single sign-on (SSO) handoff. This setting is an allow list of origins and URLs that Rayfin can redirect to after an authentication flow.
The setting supports two scenarios:
- The Fabric SSO
postMessagehandoff. - Standard authentication callbacks.
Configure the setting for both a local development app and a deployed Fabric app.
Configure allowedRedirectUris
Add allowedRedirectUris under services.auth in rayfin/rayfin.yml:
services:
auth:
enabled: true
allowedRedirectUris:
- http://localhost:5173
| Field | Type | Default | Description |
|---|---|---|---|
allowedRedirectUris |
string[] |
["http://localhost:5173"] |
Allowed redirect URIs for authentication callbacks and the Fabric SSO handoff. Include the bare origin for Fabric authentication. |
Understand how Fabric SSO uses the origin
The Fabric SSO popup flow uses your app's bare origin as the target origin for its postMessage handoff. A bare origin includes the scheme, host, and optional port, but no path. For example:
http://localhost:5173
The value must match the returnOrigin passed to the Fabric authentication provider. For the complete sign-in flow, see Configure Fabric SSO authentication.
Add each origin where your app is served. In most projects, this list includes the local development server and one or more deployed hosting origins.
Understand what rayfin up adds
When you enable static hosting, npx rayfin up automatically adds the hosting URL's bare origin to allowedRedirectUris during every deployment. You don't need to add the deployed origin manually.
The deployed origin is required for the Fabric SSO postMessage handoff, including when you disable interactive Fabric authentication.
For example, if the deployed hosting URL is https://bold-river-a3f1bc9d02-westus2.webapp.example.com, the configuration contains both the local and deployed origins after deployment:
services:
auth:
allowedRedirectUris:
- http://localhost:5173
- https://bold-river-a3f1bc9d02-westus2.webapp.example.com
The deployment command updates rayfin.yml and sends the configuration to the backend. As a result, rayfin.yml typically gains a Fabric-hosted entry after the first deployment.
Keep the allow list tightly scoped
Treat allowedRedirectUris as a security boundary. Every listed origin can receive a Fabric SSO handoff or complete an authentication callback for your app.
- Add only origins where you serve your app.
- Don't add wildcard or third-party origins.
- Review the list after you copy
rayfin.ymlbetween projects or environments. - Remove stale deployment origins after you confirm that the app no longer uses them.
A stale origin from another project or deployment can become an unintended redirect target.
Apply configuration changes
After you change allowedRedirectUris, deploy the updated configuration:
npx rayfin up
The new redirect URIs aren't available to the deployed authentication service until you apply the configuration.
Troubleshoot redirect URIs
Fabric SSO reports an origin mismatch
Confirm that:
returnOriginis a bare origin with no path.returnOriginexactly matches an entry inallowedRedirectUris.- The deployed hosting origin is present after
npx rayfin up. - The scheme, host, and port match, including the local development port.
For additional SSO diagnostics, see Troubleshoot authentication issues.
Configuration changes don't take effect
Run npx rayfin up to send the updated rayfin.yml configuration to the backend. Then retry the authentication flow.
The list contains an unfamiliar origin
Determine whether the origin belongs to a current local development server or deployed Fabric app. If it doesn't, remove it from the configuration, run npx rayfin up, and verify authentication from each expected environment.
Use an AI prompt
Copy the following prompt into GitHub Copilot or another coding agent that has access to your project:
Look at services.auth.allowedRedirectUris in my Rayfin project's rayfin/rayfin.yml.
List every origin currently in it and tell me, for each one, whether it looks like my local
development server, a Fabric-hosted deployment origin that rayfin up added automatically,
or something else that shouldn't be there. Flag anything that isn't clearly one of my own
app's origins, and propose a trimmed list. Do not remove entries without showing me the
before-and-after diff first.