SSO Tokens

Last updated: September 30, 2026

Issue a one-time token on your server, then put it on the widget’s script tag as data-sso-token. The widget exchanges it and the member lands in chat already signed in. The Quick Start covers the whole flow, including what the visitor sees and how to sign them out.

Issue a token

POST https://api.brokerbot.ai/auth/generate-token

curl -X POST https://api.brokerbot.ai/auth/generate-token \
  -H "Authorization: Bearer $BROKERBOT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]"}'

This endpoint is server-to-server only. It doesn’t allow browser (CORS) requests.

Request body:

Field Type Description
email string Member’s email. Send email, phone, or both.
phone string Member’s phone number, in any common format. It is normalized to E.164.

If both are sent, the member is looked up by email. The member must already be on your team or one of its sub-teams; this endpoint never creates members.

Response (200):

{
  "token": "eyJhbGciOiJIUzI1NiIs...",
  "expiresAt": 1790725200
}
Field Description
token The one-time token. Put it in data-sso-token.
expiresAt When the token expires, as a Unix timestamp in seconds. Tokens last 5 minutes.

Tokens work once and only on widgets that belong to your team. Issue a new one on every page render and never cache it.

Errors:

Status Meaning
400 Missing or invalid email or phone, or the body isn’t JSON.
401 Missing or invalid API key.
404 No member of your team matches this email or phone.
422 The member has no email address. Widget sign-in needs one.

TypeScript / JavaScript

import { BrokerBot } from "brokerbot"

const brokerbot = new BrokerBot({ apiKey: process.env.BROKERBOT_API_KEY! })

const { token, expiresAt } = await brokerbot.generateToken({
  email: "[email protected]"
})