跳到主要内容

无缝认证示例

企业合作伙伴可以跳过嵌入端登录表单。检查 useICCandleAuth() 的 isAuthenticated;若已为 true,复用现有会话。仅当其为 false 时,才由后端调用 get-user-token,并用返回的令牌加载 /{locale}/sign-in。

不要把企业 API 密钥写进宿主页 — 调用你自己的接口,由该接口携带密钥转发邮箱。接口约定、速率限制与查询参数见 无缝用户认证 → 步骤 5。

import { useICCandleAuth } from "@iccandle/reactjs-widget";

const EMBED_ORIGIN = "https://embed-iccandle-app.iccandle.ai";
const locale = "en";
const theme = "light";

type UserTokenResponse = {
email: string;
created: boolean;
idToken?: string;
accessToken?: string;
refreshToken?: string;
expiresIn: number;
tokenType: "Bearer";
};

const { isAuthenticated } = useICCandleAuth();

async function signUserIntoWidget(
iframe: HTMLIFrameElement,
email: string,
) {
// Check auth — reuse the live session; do not mint a new token.
if (isAuthenticated) {
iframe.src = `${EMBED_ORIGIN}/${locale}?theme=${theme}&header=true`;
return;
}

// Generate a token on your server. The host page should only receive the tokens.
const response = await fetch("https://api.iccandle.ai/seamless-auth/get-user-token", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ email }),
});
const data = (await response.json()) as UserTokenResponse;
const { idToken, accessToken, refreshToken } = data;

if (!idToken || !accessToken || !refreshToken) {
throw new Error("seamless-auth did not return tokens");
}

const params = new URLSearchParams({
id_token: idToken,
access_token: accessToken,
refresh_token_param: refreshToken,
theme,
header: "true",
});

iframe.src = `${EMBED_ORIGIN}/${locale}/sign-in?${params.toString()}`;
}

从你的后端调用 POST https://api.iccandle.ai/seamless-auth/get-user-token,并带上企业 API 密钥。