Auth
Authenticate user on your platform
Endpoint: /action/auth
Lets a third-party application authenticate the currently logged-in WalletTwo user. The action generates a short-lived one-time token tied to that user's session and delivers it back to the host page through either a postMessage event or a redirect.
This is the first action most integrations need. You use it to know who the user is on your side without having to manage credentials yourself.
Required user state
Before this action runs, the router guarantees:
User is logged in
LoggedMiddleware
/auth/login
Email is verified
EmailVerifiedMiddleware
/auth/email/verify
Wallet is created
WalletMiddleware
/auth/wallet/register
If any check fails, the iframe navigates to the appropriate onboarding screen inside the iframe. Your host page should handle this gracefully (see section below).
Iframe URL
https://<WALLETTWO_ORIGIN>/action/auth?iframe=trueOptional parameters:
redirect_uri
string (absolute URL)
If provided, the iframe navigates to this URL after the token is generated
iframe
"true"
Activates bare rendering mode (no branded container, no logo). Always include this for embedded use
Full example with redirect:
https://<WALLETTWO_ORIGIN>/action/auth?iframe=true&redirect_uri=https%3A%2F%2Fexample.com%2Fwallettwo%2FcallbackWhat happens when the action runs
The view immediately calls
client.oneTimeToken.generate().On success, it fires
window.parent.postMessage(...)to the parent window.If
redirect_uriwas supplied, the iframe navigates to that URL with additional query params appended.On failure, the user sees a toast error (no redirect, no postMessage).
The iframe itself shows a looping animation video + "Redirecting…" text while the token is being generated.
postMessage event
Sent to window.parent as soon as the one-time token is ready.
event
Always "wallet_login"
type
Always "wallet_login" (legacy alias, same value)
code
The one-time token. Exchange this on your backend immediately
user
WalletTwo internal user ID
wallet
The user's wallet address
The token is short-lived. Exchange it server-side as soon as your listener receives the event.
redirect_uri callback
If redirect_uri is present, the iframe navigates to:
code
Same one-time token delivered via postMessage
usr
WalletTwo user ID
wlt
Wallet address
Host page integration
Handling auth onboarding inside the iframe
If the user is not yet logged in or has not completed setup, the iframe will navigate through WalletTwo's auth flow before the auth action runs. Your host page will not receive a wallet_login event until that flow is complete.
Recommended approach:
Keep the iframe visible and appropriately sized so onboarding screens render correctly.
Do not set a short timeout and treat silence as failure.
Optionally, listen for the event and set a reasonable timeout (for example, 5 minutes).
Security checklist
Always verify
event.originagainst your known WalletTwo origin before trusting any message.Never log or persist the
codetoken client-side; exchange it server-side immediately.Your backend must verify the one-time token with WalletTwo before creating a session.
Validate that
userandwalletin the callback match the values returned by your token verification call.
Last updated