Skip to main content
Every time the widget opens, it needs an access token. Your server signs the token with your SECRET_KEY, and the token says which of your members is using the widget. The widget reads the token, links the session to that member’s Bluprynt organization, and never asks them to sign in a second time.

Token format

The access token is a JWT signed with HMAC-SHA256 (HS256), using your SECRET_KEY as the key. The header is {"alg":"HS256"}. No other claims are needed.

Choosing sub

Bluprynt uses sub to find the member’s organization, KYB result, assets and wallets. The same sub always reopens the same progress.

Build a token endpoint

Expose one authenticated POST route that returns { "accessToken": "..." }. Every example below follows the same rules:
  • It reads the member ID from your authenticated session, never from the request body.
  • It returns 401 when nobody is signed in.
  • It returns 503 when the partner ID or secret isn’t configured.
  • It sends Cache-Control: no-store, so no browser or proxy caches a token.
The Node.js and Python versions produce the same token. Bluprynt tested both against the production widget: a PyJWT token built exactly as above opens the same drawer as one from generateToken().

Other languages

Any JWT library that supports HS256 works. Sign { sub, iss, iat, exp } with your SECRET_KEY as a UTF-8 string key. For example:

Call the endpoint from the browser

Lifetime

  • Mint a new token every time you call kyi(). Don’t store tokens in localStorage, cookies or global state.
  • Keep the lifetime short. The default 3600 seconds gives a member an hour to finish a session. You don’t need more: progress is saved against sub, so a new token with the same sub resumes where they stopped.
  • Rotate your SECRET_KEY through your Bluprynt contact if it may have leaked. Tokens signed with the old key stop working.

Test your token

Decode the token without verifying it, and check its claims before you call kyi():
Related: Security · Errors and troubleshooting · API reference