Skip to main content
POST
Start flow

Authorizations

Authorization
string
header
required

Use your Authsignal Server API secret key as the username and leave the password empty. The secret key can be found in the API Keys section of the Authsignal Portal settings page.

Body

application/json
actionCode
string
required

A short human-readable code which defines the action that the user is performing, e.g. signIn. This must match the value that you entered when creating the flow in the Authsignal Portal.

user
object

An identifier used to lookup a user. Provide exactly one of userId, email, phoneNumber, or username. If no user exists in Authsignal for the provided identifier then a record will be created.

attributes
object
redirectUrl
string

Where Authsignal redirects the user after they complete the flow via the pre-built UI. Only required if using the pre-built UI in redirect mode.

clientId
string

The ID of the app client configured in the Authsignal Portal. Required if you're using Authsignal's session management to issue access tokens or refresh tokens.

Response

OK

action
object
required
challengeToken
string
required

A token which can be used if integrating using client SDKs. Whenever a verification or enrollment step in a flow is completed, the old challenge token will be invalidated and a new challenge token issued. Always send the latest challenge token in your requests.

challengeUrl
string
required

A URL which can be used to launch this flow instance in the pre-built UI.

user
object