Authn.tech
Home
  • SAML 2.0
  • OAuth 2.0
  • OIDC
  • JWT / JOSE
  • WebAuthn / Passkey
  • MFA / TOTP
  • LDAP
  • China Platforms SSO
  • All Tools
  • JWT Decode
  • JWT Sign
  • JWK Gen
  • JWK → PEM
  • PEM → JWK
  • PKCE Gen
  • OIDC Discovery
  • Scan-Login Demo
  • TOTP
  • WebAuthn
  • SAML Codec
  • SAML Metadata
  • SAML Response
  • Feishu SAML
  • X.509 Cert
  • PEM Inspect
  • Base64URL
  • LDAP Filter
  • Overview & Roles
  • OIDC Mock
  • SAML Mock
  • Mail Server
  • LDAP Directory
  • OIDC Login Demo
  • SAML Login Demo
  • WeChat Scan-Login
  • WeCom Scan-Login
  • 简体中文
  • English
  • Deutsch
GitHub
Home
  • SAML 2.0
  • OAuth 2.0
  • OIDC
  • JWT / JOSE
  • WebAuthn / Passkey
  • MFA / TOTP
  • LDAP
  • China Platforms SSO
  • All Tools
  • JWT Decode
  • JWT Sign
  • JWK Gen
  • JWK → PEM
  • PEM → JWK
  • PKCE Gen
  • OIDC Discovery
  • Scan-Login Demo
  • TOTP
  • WebAuthn
  • SAML Codec
  • SAML Metadata
  • SAML Response
  • Feishu SAML
  • X.509 Cert
  • PEM Inspect
  • Base64URL
  • LDAP Filter
  • Overview & Roles
  • OIDC Mock
  • SAML Mock
  • Mail Server
  • LDAP Directory
  • OIDC Login Demo
  • SAML Login Demo
  • WeChat Scan-Login
  • WeCom Scan-Login
  • 简体中文
  • English
  • Deutsch
GitHub
  • Online Tools

    • All Tools
    • JWT / JWK

      • JWT Decode
      • JWT Sign
      • JWK Gen
      • JWK → PEM
      • PEM → JWK
    • OAuth2 / OIDC

      • PKCE Gen
      • Discovery
      • Scan-Login Demo
    • MFA / Passkey

      • TOTP
      • WebAuthn
    • SAML

      • SAML Codec
      • SAML Metadata
      • SAML Response
      • Feishu SAML
    • Certs / Encoding

      • X.509 Cert
      • PEM Inspect
      • Base64URL
    • LDAP

      • LDAP Filter

WeChat / WeCom Scan-Login Demo

A fully in-browser, clickable, real scan-login demo. It embeds a QR code with a Mock SDK that is byte-for-byte identical to the official one (WxLogin / WwLogin), runs the full authorization-code flow, and finally exchanges and displays the user info on this page. Use the tabs below to pick "WeChat (Website App)" or "WeCom".

How to use it

  1. Pick a platform → click "Show login QR code";
  2. Scan with your phone, or click the "(dev) simulate scan → confirm" link under the QR;
  3. The page returns with a code, validates state, then calls the Mock backend:
    • WeChat: /sns/oauth2/access_token → /sns/userinfo;
    • WeCom: /cgi-bin/gettoken → /cgi-bin/auth/getuserinfo → /cgi-bin/user/get.

The whole exchange runs locally in your browser (the Mock has CORS enabled). It targets this site's Mock service by default; the input at the top lets you point it at your own deployment.

Go deeper

  • 📖 Protocol: WeChat scan-login · WeCom scan-login — what the JS SDK does, why you'd use it, why WeCom takes three steps
  • 🧪 Mock usage: Mock WeChat · Mock WeCom — endpoints, integration code and "going live = change only JS + URL"

Test-only

The Mock returns a fixed user/member, the authorization code is a short-lived, reusable self-signed JWT, and the signing key is public. Never use it in production.

Last updated: 7/22/26, 1:48 PM
Contributors: linux, Claude Opus 4.8
Prev
Discovery