Developer documentation

Authenticate customer

post https://app.iteras.dk/api/authenticatecustomer/

The /api/authenticatecustomer/ endpoint checks if a given customer id/email + password combination is valid, and return the id of the corresponding customer.

Since the Iteras server doesn't know the origin of the parameters provided, there is no intrinsic rate limit. Hence, if you connect an internet-facing application to this endpoint, you should put in a rate limit to prevent hacking by exhaustive search.

Parameters

You must provide the password and either id or email.

  • id string
    Customer ID, e.g. id=12345.
  • email string
    Customer email, e.g. email=somebody@example.com.
  • password string required
    Customer password, e.g. secret, or a one-time password.
  • preauthseconds integer
    Request a pre-authentication token valid for given seconds, e.g. 3600.

Return value

The data returned is an object with authenticated: true and the ID of the customer like this:

{
  "authenticated": true,
  "id": "12345"
}

Or if authentication fails:

{
  "authenticated": false,
  "errorcode": "unknowncustomer"
}

or

{
  "authenticated": false,
  "errorcode": "invalidpassword"
}

Both failure responses above return with an HTTP 200 status code. Missing id/email or password is not a failed authentication but a malformed request, and returns a plain text HTTP 400 error.

Pre-authentication token

If you specify preauthseconds, you'll get back a pre-auth token in the reply in case the user is authenticated, e.g.:

{
  "authenticated": true,
  "id": "12345",
  "preauth": "Azxd123:JOIj123:JOjOIJASDF"
}

This token is only valid for the number of seconds you specified. When the pre-auth token is given to the iframe-generating JS API it causes the customer to be logged in automatically without being presented with a login screen:

Iteras.selfserviceiframe({ profile: "myprofile", preauth: "Azxd123:JOIj123:JOjOIJASDF" })

This is sometimes a useful building-block for a single-sign-on site.

If you need to redirect the customer to another page, it's also possible to append the returned pre-auth token as the iteraspreauth GET parameter. For instance, if you put in a link to https://example.com/otherpage/?iteraspreauth=Azxd123%3AJOIj123%3AJOjOIJASDF and /otherpage/ contains an embedded self-service iframe, Iteras will automatically pickup the parameter and pass it to the embedded iframe.

Redirecting to a stand-alone self-service page not inside an iframe also accepts the iteraspreauth GET parameter.