PageSourceSearch

https://authress.io/knowledge-base/assets/js/94cd7b07.631fdf6f.js

js authress.io collected 2026-09-24 18:29:55 UTC 10,378 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkAuthressKnowledgeBase=self.webpackChunkAuthressKnowledgeBase||[]).push([[2481],{3905:(e,t,n)=>{n.d(t,{Zo:()=>c,kt:()=>d});var i=n(67294);function o(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function a(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);t&&(i=i.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,i)}return n}function r(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?a(Object(n),!0).forEach((function(t){o(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):a(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function s(e,t){if(null==e)return{};var n,i,o=function(e,t){if(null==e)return{};var n,i,o={},a=Object.keys(e);for(i=0;i<a.length;i++)n=a[i],t.indexOf(n)>=0||(o[n]=e[n]);return o}(e,t);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);for(i=0;i<a.length;i++)n=a[i],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(o[n]=e[n])}return o}var l=i.createContext({}),u=function(e){var t=i.useContext(l),n=t;return e&&(n="function"==typeof e?e(t):r(r({},t),e)),n},c=function(e){var t=u(e.components);return i.createElement(l.Provider,{value:t},e.children)},p={inlineCode:"code",wrapper:function(e){var t=e.children;return i.createElement(i.Fragment,{},t)}},h=i.forwardRef((function(e,t){var n=e.components,o=e.mdxType,a=e.originalType,l=e.parentName,c=s(e,["components","mdxType","originalType","parentName"]),h=u(n),d=o,m=h["".concat(l,".").concat(d)]||h[d]||p[d]||a;return n?i.createElement(m,r(r({ref:t},c),{},{components:n})):i.createElement(m,r({ref:t},c))}));function d(e,t){var n=arguments,o=t&&t.mdxType;if("string"==typeof e||o){var a=n.length,r=new Array(a);r[0]=h;var s={};for(var l in t)hasOwnProperty.call(t,l)&&(s[l]=t[l]);s.originalType=e,s.mdxType="string"==typeof e?e:o,r[1]=s;for(var u=2;u<a;u++)r[u]=n[u];return i.createElement.apply(null,r)}return i.createElement.apply(null,n)}h.displayName="MDXCreateElement"},49785:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>p,frontMatter:()=>a,metadata:()=>s,toc:()=>u});var i=n(87462),o=(n(67294),n(3905));const a={sidebar_label:"Extension authentication",title:"Extension authentication",description:"How do users log into extensions and managing extension authentication.",image_alt:"Extension authentication"},r=void 0,s={unversionedId:"extensions/extension-authentication",id:"extensions/extension-authentication",title:"Extension authentication",description:"How do users log into extensions and managing extension authentication.",source:"@site/docs/40-extensions/40-extension-authentication.md",sourceDirName:"40-extensions",slug:"/extensions/extension-authentication",permalink:"/knowledge-base/docs/extensions/extension-authentication",draft:!1,editUrl:"https://gitlab.com/rhosys/authress-public-kb/knowledge-base/-/blob/main/docs/40-extensions/40-extension-authentication.md",tags:[],version:"current",lastUpdatedAt:1772377859,formattedLastUpdatedAt:"Mar 1, 2026",sidebarPosition:40,frontMatter:{sidebar_label:"Extension authentication",title:"Extension authentication",description:"How do users log into extensions and managing extension authentication.",image_alt:"Extension authentication"},sidebar:"tutorialSidebar",previous:{title:"Installing extensions",permalink:"/knowledge-base/docs/extensions/installing-extensions"},next:{title:"CI/CD Automation",permalink:"/knowledge-base/docs/cicd/"}},l={},u=[{value:"Extensions logging users in",id:"extensions-logging-users-in",level:3},{value:"Extensions accessing user data",id:"extensions-accessing-user-data",level:3}],c={toc:u};function p(e){let{components:t,...n}=e;return(0,o.kt)("wrapper",(0,i.Z)({},c,n,{components:t,mdxType:"MDXLayout"}),(0,o.kt)("p",null,"After a user has enabled an extension for their account. They'll likely navigate to the extension to configure it. To do so they might go to a website created by the extension developer. That website will ask them to log in with their ",(0,o.kt)("inlineCode",{parentName:"p"},"Platform Identity"),". This will direct them to your Authress managed login page to log in."),(0,o.kt)("p",null,"Your users will want to log in to these third party built solutions, using their ",(0,o.kt)("inlineCode",{parentName:"p"},"platform identity"),". The user's ",(0,o.kt)("inlineCode",{parentName:"p"},"platform identity")," comes from logging in using SSO via your Authress account. Instead of your users logging into your platform, here the users will log into the extension portal. The ",(0,o.kt)("inlineCode",{parentName:"p"},"extension identity")," is mapped from the user's existing ",(0,o.kt)("inlineCode",{parentName:"p"},"platform identity"),"."),(0,o.kt)("p",null,"The user's ",(0,o.kt)("inlineCode",{parentName:"p"},"extension identity")," is used by the extension to verify they are who they say they are, and the extension developers will do this verification using the exact same ",(0,o.kt)("a",{parentName:"p",href:"/knowledge-base/docs/authentication/validating-jwts"},"JWT verification")," that you do in your services to verify Authress JWTs. The JWT verification can be easily done using the ",(0,o.kt)("inlineCode",{parentName:"p"},"verifyToken")," method or the ",(0,o.kt)("inlineCode",{parentName:"p"},"TokenVerifier")," class found in each of the ",(0,o.kt)("a",{parentName:"p",href:"https://authress.io/app/#/api"},"Authress SDKs"),". (See ",(0,o.kt)("a",{parentName:"p",href:"/knowledge-base/docs/authentication/validating-jwts"},"verifying Authress JWTs")," for more information.)"),(0,o.kt)("p",null,"Specifically the difference between the ",(0,o.kt)("inlineCode",{parentName:"p"},"platform identity")," JWT and the ",(0,o.kt)("inlineCode",{parentName:"p"},"extension identity")," JWT is the ",(0,o.kt)("inlineCode",{parentName:"p"},"issuer")," claim in the token."),(0,o.kt)("ul",null,(0,o.kt)("li",{parentName:"ul"},"User's platform identity JWT issuer: ",(0,o.kt)("inlineCode",{parentName:"li"},"https://auth.yourdomain.com")),(0,o.kt)("li",{parentName:"ul"},"Extension identity JWT issuer: ",(0,o.kt)("inlineCode",{parentName:"li"},"https://auth.yourdomain.com/api/extensions/ext_001"))),(0,o.kt)("p",null,"This prevents accidental usage of the extension JWTs within your platform. When the extension wants to request access to your platform's data on behalf of the customer account. The extension will generate a JWT using their service client and the generated ",(0,o.kt)("a",{parentName:"p",href:"#installing-extensions"},"API access token")," they received when creating the extension."),(0,o.kt)("h3",{id:"extensions-logging-users-in"},"Extensions logging users in"),(0,o.kt)("p",null,"Extension authentication is OAuth2.1 compliant, and the ",(0,o.kt)("a",{parentName:"p",href:"https://www.npmjs.com/package/@authress/login"},"Authress Login SDK")," makes this easy for your extension developers to build a UI that enables login via your ",(0,o.kt)("inlineCode",{parentName:"p"},"platform identities"),". Follow the ",(0,o.kt)("a",{parentName:"p",href:"https://authress.io/app/#/api?route=get-/"},"Authress OAuth API")," documentation or use this quick setup re
1commendation for your extension developers to enable login with your platform. We recommend wrapping this code snippet in a custom UI library that you can distribute or providing clear API documentation that matches the OAuth code samples that are in our OAuth API documentation:"),(0,o.kt)("ul",null,(0,o.kt)("li",{parentName:"ul"},(0,o.kt)("a",{parentName:"li",href:"https://authress.io/app/#/api?route=get-/"},"OAuth create login request")),(0,o.kt)("li",{parentName:"ul"},(0,o.kt)("a",{parentName:"li",href:"https://authress.io/app/#/api?route=post-/api/authentication/oauth/tokens"},"OAuth complete login request"))),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-js",metastring:'title="Extension UI user login example"',title:'"Extension',UI:!0,user:!0,login:!0,'example"':!0},"import { ExtensionClient } from '@authress/login';\n\nconst extensionClient = new ExtensionClient('https://login.application.io', extensionId);\n\n// redirectUrl is where the extension would like to return the user to after login\n// * This method will redirect the user to the Authress Login UI screen with an auth code\nconst { accessToken } = await extensionClient.login(redirectUrl);\n\n// .... After login the user is redirected to the redirectUrl\n// * So try the login again:\nconst { accessToken } = await extensionClient.login(redirectUrl);\n\n// * Or get the user claims from the token\nawait userData = await this.getUserIdentity();\n")),(0,o.kt)("h3",{id:"extensions-accessing-user-data"},"Extensions accessing user data"),(0,o.kt)("p",null,"For your extension developers to use these access tokens to call your API, Authress recommends building your SDK. There are instructions for doing this in the ",(0,o.kt)("a",{parentName:"p",href:"/knowledge-base/docs/authorization/service-clients/access-keys/#building-a-client-sdk"},"building a client SDK")," section."),(0,o.kt)("p",null,"The relevant code snippet from that guide is:"),(0,o.kt)("pre",null,(0,o.kt)("code",{parentName:"pre",className:"language-js",metastring:'title="Your client SDK (or CLI)"',title:'"Your',client:!0,SDK:!0,"(or":!0,'CLI)"':!0},"import { ServiceClientTokenProvider } from '@authress/sdk';\n\n// Configure the custom domain: https://authress.io/app/#/settings?focus=domain\nconst authressCustomDomainUrl = 'https://auth.yourdomain.com';\n\nclass myApplicationServiceClient {\n  // The customersSecretAccessToken is the private key you generated from Authress\n  // to give to your customer as an API key.\n  // Generate these by creating a service client and access key at:\n  // https://authress.io/app/#/api?route=post-/v1/clients/-clientId-/access-keys\n  async sdkApiCall() {\n    const tokenProvider = new ServiceClientTokenProvider(\n      customersSecretAccessToken, authressCustomDomainUrl);\n    const token = await tokenProvider.getToken();\n    const headers = { Authorization: `Bearer ${token}` };\n    return httpClient.get(url, headers);\n  }\n}\n")))}p.isMDXComponent=!0}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.