Email/SMS Authentication
One-Time Passcodes and Magic Links can be sent via email or phone. Passage highly recommends using One-Time Passcodes over Magic Links, they are easier to implement, more secure, and they provide a better user experience.
Login codes
A one-time passcode(OTP) is a code that is sent to a user via email or SMS. While authenticating, a user will input the passcode to complete login or registration.
Send registration passcode to user
To create a new passcode for registration and send to users, call passage.oneTimePasscode.register()
with a user's email address or phone number. A successful call will return a OTP id. The id will be used when you activate the OTP.
String otpId = await passage.newRegisterOneTimePasscode(identifier);
Send login passcode to user
To create a new passcode for login and send to users, call passage.oneTimePasscode.login()
with a user's email address or phone number. A successful call will return a OTP id. The id will be used when you activate the OTP.
String otpId = await passage.newLoginOneTimePasscode(identifier);
Activate passcode
When the user inputs their OTP into your app, you will send their OTP input string and OTP id through passage.oneTimePasscode.activate
, which will return an AuthResult
containing your user's tokens (which are automatically stored securely on device).
AuthResult authResult = await passage.oneTimePasscode.activate(otp, otpId);
Magic Links
Magic Links are hyperlinks that are sent to a user via email or SMS. Clicking the link authenticates your users and redirects them to your app.
Send registration Magic Link to user
To create a new Magic Link for registration and send to users, call passage.magicLink.register()
with a user's email address or phone number. A successful call will return a Magic Link id. The id will be used when you activate the link and check the link status.
String magicLinkId = await passage.magicLink.register(identifier);
Send login Magic Link to user
To create a new Magic Link for login and send to users, call passage.magicLink.login()
with a user's email address or phone number. A successful call will return a Magic Link id. The id will be used when you Activate the link.
String magicLinkId = await passage.magicLink.login(identifier);
Activate Magic Link in app
iOS Prerequisite: Setup Universal Linking (opens in a new tab)
Android Prerequisite: Setup App Links (opens in a new tab)
Web Prerequisite: Setup URL Strategy (opens in a new tab)
When the user taps/clicks on the Magic Link url follow these steps:
- Parse out the Magic Link:
Uri uri = Uri.parse(passageMagicLinkUri);
String magicLink = uri.queryParameters['psg_magic_link'];
- Pass that Magic Link string to
passage.magicLink.activate()
to validate. On success, this method will return anAuthResult
containing your user's tokens (which are automatically stored securely on device).
AuthResult authResult = await passage.magicLink.activate(magicLink);
Check Magic Link status
If the user opens the Magic Link on a different device or browser than where they initially requested the Magic Link, you can continually check the status of the link in your app. Once the Magic Link has been activated, passage.getMagicLinkStatus
will return an AuthResult
and save the user's tokens securely on device.
try {
AuthResult authResult = await passage.magicLink.status(magicLinkId);
} catch (error) {
// Magic link not activated yet, do nothing.
}