Distribution federation of PKCE
Table of Contents
Auth Domain
Due to how Firefox browsers open links on Android we MUST use a different domain from the content domain for our distribution-federated PKCE Auth. This is only a requirement when you are using our PKCE sign-in flow that we host and maintain on our server - this is because, by default, the auth and content are hosted on the same domain which is the root cause of the issue.
The domain can be anything, though we recommend something like auth.client-domain.com. This needs to be mapped to pugpig.map.fastly.net in the clients CNAME record in the same way as vanity domains.
Let your onboarder know the domain you have mapped to our Fastly account and we will set-up up in the app for you.