Skip to main content
Authsignal’s session APIs can be used to manage an authenticated session for a user.

Configuration

Enabling the JWKS URL

To use Authsignal session APIs, you must first enable a JWKS URL in the Authsignal Portal under Settings -> API keys.
Enabling a JWKS URL
Once enabled, a link to the JWKS URL for your tenant will be displayed.
Enabling a JWKS URL

Creating app clients

Next, create an app client in the Authsignal Portal under Settings -> App clients.
Creating an app client
For each client you create, you can configure a separate access token and refresh token duration. The client ID will be set as the access token’s aud claim.
App client list

Creating sessions

In order to create an authenticated session, you must first obtain an Authsignal client token either by using a Client SDK or the pre-built UI.

OTP auth (email, SMS, TOTP)

For an OTP authentication method such as Email OTP you can follow the integration steps below to create a session. 1. Backend - Track action In your app’s backend, use an Authsignal Server SDK to track an action and obtain an initial client token.
2. Frontend - Use a Client SDK In your web or mobile app, call setToken with the client token obtained in step 1, then use the relevant SDK methods to progress the user through a challenge and obtain a new client token.
3. Backend - Create session Pass the client token obtained in step 2 to your backend and exchange it for an access token and refresh token.

Passkeys

When using a device-bound authentication method like passkeys, only two steps are required to create a session. 1. Frontend - Use a Client SDK Use our web SDK to present a passkey sign-in prompt in the browser, or use one of our mobile SDKs to present the native passkey UI in an iOS or Android app.
2. Backend - Create session Pass the token obtained in step 1 to your backend and exchange it for an access token and refresh token.

Validating sessions

Using the JWKS URL

Access tokens are signed using an RS256 algorithm. A JWKS endpoint for your tenant’s keys is available at the following location:
  • The AUTHSIGNAL_URL value is the URL for your tenant’s region.
  • The AUTHSIGNAL_TENANT value is your tenant ID.

Using the SDK

You can also use the Authsignal Server SDK to validate an access token.
In addition to verifying the access token’s signature, the Authsignal SDK’s validateSession method will also check that the token has not been revoked.

Refreshing sessions

A refresh token can be exchanged for a new access token and refresh token.
Refresh tokens are single-use and should be replaced with the new refresh token returned in the response.

Revoking sessions

An individual access token can be revoked so that the validateSession method will no longer accept it.
In addition, you can revoke all currently active tokens for a user.

Next steps