Seamless auth example
Corporate partners can skip the embed login form. Check isAuthenticated from useICCandleAuth(); if it is already true, reuse the session. Only when it is false should your backend call get-user-token and load /{locale}/sign-in with the returned tokens.
Do not put the corporate API key in the host page — call your route, which forwards the email with the key. API contract, rate limits, and query params: Seamless user authentication → Step 5.
import { useICCandleAuth } from "@iccandle/reactjs-widget";
const EMBED_ORIGIN = "https://embed-iccandle-app.iccandle.ai";
const locale = "en";
const theme = "light";
type UserTokenResponse = {
email: string;
created: boolean;
idToken?: string;
accessToken?: string;
refreshToken?: string;
expiresIn: number;
tokenType: "Bearer";
};
const { isAuthenticated } = useICCandleAuth();
async function signUserIntoWidget(
iframe: HTMLIFrameElement,
email: string,
) {
// Check auth — reuse the live session; do not mint a new token.
if (isAuthenticated) {
iframe.src = `${EMBED_ORIGIN}/${locale}?theme=${theme}&header=true`;
return;
}
// Generate a token on your server. The host page should only receive the tokens.
const response = await fetch("https://api.iccandle.ai/seamless-auth/get-user-token", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ email }),
});
const data = (await response.json()) as UserTokenResponse;
const { idToken, accessToken, refreshToken } = data;
if (!idToken || !accessToken || !refreshToken) {
throw new Error("seamless-auth did not return tokens");
}
const params = new URLSearchParams({
id_token: idToken,
access_token: accessToken,
refresh_token_param: refreshToken,
theme,
header: "true",
});
iframe.src = `${EMBED_ORIGIN}/${locale}/sign-in?${params.toString()}`;
}
Call POST https://api.iccandle.ai/seamless-auth/get-user-token from your backend with the corporate API key.