login({ authToken }). AIR Kit then creates or loads the AIR Account for that email.
The first time an email is used, AIR verifies it with a one-time password sent to that address, because the email identifies the user across AIR. Later logins with the same email skip this step.
Custom Auth needs a registered JWKS endpoint, like any Partner JWT.
JWT payload
Sign the token on your server with a
kid header that matches your JWKS.
For a full implementation with backend and frontend code, see the Bring your own auth recipe.