SECRET_KEY, and the token says which of your members is using the widget. The widget reads the token, links the session to that member’s Bluprynt organization, and never asks them to sign in a second time.
Token format
The access token is a JWT signed with HMAC-SHA256 (HS256), using your SECRET_KEY as the key.
The header is
{"alg":"HS256"}. No other claims are needed.
Choosing sub
Bluprynt uses sub to find the member’s organization, KYB result, assets and wallets. The same sub always reopens the same progress.
Build a token endpoint
Expose one authenticatedPOST route that returns { "accessToken": "..." }. Every example below follows the same rules:
- It reads the member ID from your authenticated session, never from the request body.
- It returns
401when nobody is signed in. - It returns
503when the partner ID or secret isn’t configured. - It sends
Cache-Control: no-store, so no browser or proxy caches a token.
The Node.js and Python versions produce the same token. Bluprynt tested both against the production widget: a PyJWT token built exactly as above opens the same drawer as one from
generateToken().Other languages
Any JWT library that supports HS256 works. Sign{ sub, iss, iat, exp } with your SECRET_KEY as a UTF-8 string key. For example:
Call the endpoint from the browser
Lifetime
- Mint a new token every time you call
kyi(). Don’t store tokens inlocalStorage, cookies or global state. - Keep the lifetime short. The default
3600seconds gives a member an hour to finish a session. You don’t need more: progress is saved againstsub, so a new token with the samesubresumes where they stopped. - Rotate your
SECRET_KEYthrough your Bluprynt contact if it may have leaked. Tokens signed with the old key stop working.
Test your token
Decode the token without verifying it, and check its claims before you callkyi():
Related: Security · Errors and troubleshooting · API reference