Issue a one-time token on your server, then put it on the widget’s script tag as data-sso-token. The widget exchanges it and the member lands in chat already signed in. The Quick Start covers the whole flow, including what the visitor sees and how to sign them out.
Issue a token
POST https://api.brokerbot.ai/auth/generate-token
curl -X POST https://api.brokerbot.ai/auth/generate-token \
-H "Authorization: Bearer $BROKERBOT_API_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]"}'
This endpoint is server-to-server only. It doesn’t allow browser (CORS) requests.
Request body:
| Field | Type | Description |
|---|---|---|
email |
string | Member’s email. Send email, phone, or both. |
phone |
string | Member’s phone number, in any common format. It is normalized to E.164. |
If both are sent, the member is looked up by email. The member must already be on your team or one of its sub-teams; this endpoint never creates members.
Response (200):
{
"token": "eyJhbGciOiJIUzI1NiIs...",
"expiresAt": 1790725200
}
| Field | Description |
|---|---|
token |
The one-time token. Put it in data-sso-token. |
expiresAt |
When the token expires, as a Unix timestamp in seconds. Tokens last 5 minutes. |
Tokens work once and only on widgets that belong to your team. Issue a new one on every page render and never cache it.
Errors:
| Status | Meaning |
|---|---|
400 |
Missing or invalid email or phone, or the body isn’t JSON. |
401 |
Missing or invalid API key. |
404 |
No member of your team matches this email or phone. |
422 |
The member has no email address. Widget sign-in needs one. |
TypeScript / JavaScript
import { BrokerBot } from "brokerbot"
const brokerbot = new BrokerBot({ apiKey: process.env.BROKERBOT_API_KEY! })
const { token, expiresAt } = await brokerbot.generateToken({
email: "[email protected]"
})