Documentation

Ciright documentation

KEYRA is not a full replacement for every login system by default. Use OAuth Verify for hosted passwordless access, or Partner 2FA to add step-up approval to an existing login. Ciright Core still decides application rights after Keyra verifies the participant.

OAuth VerifyPasswordless authentication

Start in the browser; validate on your server before issuing a Ciright session.

Keyra OAuth Verify overview

Partner 2FAStep-up on existing login

Keep username/email auth; enroll and step-up with Keyra. Do not treat this as Ciright account creation.

Ciright-specific

  • Resolve Application ID, Subscription ID, UID and EID on the server.
  • A country parameter never confers privileges.
  • Sandbox credentials cannot authorize production actions.
  • Reference workflow: approve a sandbox configuration change.
<script src="https://auth.keyra.ie/sdk/keyra-oauth.js"></script>
<script>
  KeyraOAuth.renderButton("#keyra-login", {
    clientId: "cp_test_YOUR_PUBLISHABLE_KEY",
    authOrigin: "https://auth.keyra.ie",
    redirectUri: "https://YOUR_REGISTERED_CALLBACK/api/auth/keyra/callback",
    scope: "verify",
    mode: "popup",
    appearance: { theme: "black", text: "login_with" }
  });
</script>

Never put a secret key (sk_test_ / sk_prod_) in browser examples. POST /oauth/token requires grant_type, code, redirect_uri, and code_verifier. redirect_uri must match the Keyra project callback.