Skip to main content

Seamless auth for sub-org users

Platforms (or client / broker backends) can create and authenticate end users under a specific broker identifier. Calling this endpoint associates the user with that client / broker so they appear in the Organization Users embed, where the broker can assign a plan.

This is different from corporate seamless auth, which uses get-user-token without an identifier.

Backend calls get-user-token-sub-org
(email + identifier + X-Api-Key)
↓
User is created / authenticated under that broker
↓
User appears in
https://manage.iccandle.site/?apikey=…&identifier=…
↓
Broker assigns a plan in the Organization Users panel

Prerequisites​

RequirementDetails
API keyIssued in the platform admin dashboard — see API Keys
Broker identifierSame value the client uses in the Organization Users embed
End-user emailEmail of the user to create or authenticate
Server-side callerKeep the API key and tokens off public clients

Authentication flow​

  1. Your backend sends POST to get-user-token-sub-org with the user's email and the broker's identifier.
  2. Authenticate the request with X-Api-Key.
  3. On success, the response includes session tokens (idToken, accessToken, refreshToken).
  4. The user is linked to that broker's organization.
  5. Open the broker's embed at https://manage.iccandle.site/ with the matching apikey and identifier — the user shows in the list.
  6. The broker assigns a plan from their credit bundle.

Organization Users embed listing end users after sub-org seamless auth

Get user token (sub-org)​

POST https://api.iccandle.ai/seamless/get-user-token-sub-org
X-Api-Key: <your-api-key>
Content-Type: application/json

Request body:

{
"email": "user@example.com",
"identifier": "A broker"
}
FieldTypeRequiredDescription
emailstringYesEnd-user email to create or authenticate
identifierstringYesClient / broker organization id — must match the embed identifier

Response:

{
"email": "user@example.com",
"created": false,
"idToken": "",
"accessToken": "",
"refreshToken": "",
"expiresIn": 86400,
"tokenType": "Bearer"
}
FieldTypeDescription
emailstringThe email the session belongs to
createdbooleantrue when this request created a new iC Candle user for the email
idTokenstringIdentity token for the user
accessTokenstringToken used to invoke iC Candle APIs
refreshTokenstringToken used to refresh the session
expiresInnumberSession lifetime in seconds (86400 = 24 hours)
tokenTypestringAlways Bearer

Example call:

curl -X POST \
https://api.iccandle.ai/seamless/get-user-token-sub-org \
-H "X-Api-Key: $ICCANDLE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email": "user@example.com", "identifier": "A broker"}'
Keep the key server-side

Call this endpoint only from your backend. Do not put the API key in browser code, mobile apps, or the Organization Users iframe URL beyond what the broker already uses for the manage panel.

After authentication — Organization Users embed​

Use the same identifier in the embed URL that you sent in the request body:

https://manage.iccandle.site/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER&theme=system&lang=zh&primary=57F63B
StepWhoAction
1BackendCall get-user-token-sub-org with email + identifier
2BrokerOpen / refresh the Organization Users panel for that identifier
3BrokerFind the user in the list
4BrokerOpen the user drawer and Assign a plan

Until a plan is assigned, the user shows as No plan and does not consume a credit from the bundle. Plan assignment draws one credit of the selected tier — see Clients / Brokers and Top Up Clients.

Using tokens with widgets​

The response token shape matches corporate seamless auth. After you have idToken, accessToken, and refreshToken, you can sign the user into the iC Candle widget the same way as in Seamless user authentication (Step 5 — sign the user into the widget).

Compared with corporate seamless auth​

Corporate get-user-tokenPlatform sub-org get-user-token-sub-org
EndpointPOST /seamless-auth/get-user-tokenPOST /seamless/get-user-token-sub-org
Body{ "email" }{ "email", "identifier" }
Org contextCorporate account of the API keyExplicit broker identifier
Where users are managedCorporate consoleOrganization Users embed
Who grants plansCorporate partnerClient / broker in the embed