How it works
- Your app authenticates the user through your own system.
- Your backend signs a Partner JWT containing the user’s
email. - Your frontend passes that JWT to
airService.login({ authToken }). - AIR Kit creates or loads the user’s AIR Account, skipping the built-in login UI.
The first time an email is used, AIR verifies it with a one-time password. Later logins with that email skip this step.
Prerequisites
- AIR Kit SDK installed and initialized. See Web SDK.
- A Partner JWT signing key, with its public key published through a registered JWKS endpoint.
- The authenticated user’s email address available on your backend.
Step 1: Generate a Partner JWT on your backend
Includeemail and partnerId:
Step 2: Fetch the token and log in on the frontend
Step 3: Use AIR Kit features normally
After login, all SDK methods work as usual — issue credentials, verify credentials, access smart accounts:Next steps
- Custom Auth for the JWT payload reference
- SDK authentication for signing in other languages
- Sessions & user info and MFA