Skip to main content
With Custom Auth, users who are already signed in to your app skip the AIR Kit login dialog. Your backend signs a Partner JWT that includes the user’s email, and your app passes it to login({ authToken }). AIR Kit then creates or loads the AIR Account for that email. The first time an email is used, AIR verifies it with a one-time password sent to that address, because the email identifies the user across AIR. Later logins with the same email skip this step. Custom Auth needs a registered JWKS endpoint, like any Partner JWT.

JWT payload

Sign the token on your server with a kid header that matches your JWKS. For a full implementation with backend and frontend code, see the Bring your own auth recipe.