Skip to main content
If your app already authenticates users (via Firebase, Auth0, Supabase, or a custom system), you can bypass the AIR Kit login dialog and pass the authenticated user straight into an AIR Kit session. This is called Custom Auth.

How it works

  1. Your app authenticates the user through your own system.
  2. Your backend signs a Partner JWT containing the user’s email.
  3. Your frontend passes that JWT to airService.login({ authToken }).
  4. AIR Kit creates or loads the user’s AIR Account, skipping the built-in login UI.
The first time an email is used, AIR verifies it with a one-time password. Later logins with that email skip this step.

Prerequisites

  • AIR Kit SDK installed and initialized. See Web SDK.
  • A Partner JWT signing key, with its public key published through a registered JWKS endpoint.
  • The authenticated user’s email address available on your backend.

Step 1: Generate a Partner JWT on your backend

Include email and partnerId:

Step 2: Fetch the token and log in on the frontend

The user is now logged in without the AIR Kit login dialog, apart from the one-time email check on first use. Their AIR Account is tied to the email from your system.

Step 3: Use AIR Kit features normally

After login, all SDK methods work as usual — issue credentials, verify credentials, access smart accounts:

Next steps