Start in the browser; validate on your server before issuing a Ciright session.
Documentation
Ciright documentation
KEYRA is not a full replacement for every login system by default. Use OAuth Verify for hosted passwordless access, or Partner 2FA to add step-up approval to an existing login. Ciright Core still decides application rights after Keyra verifies the participant.
Keep username/email auth; enroll and step-up with Keyra. Do not treat this as Ciright account creation.
Ciright-specific
- Resolve Application ID, Subscription ID, UID and EID on the server.
- A country parameter never confers privileges.
- Sandbox credentials cannot authorize production actions.
- Reference workflow: approve a sandbox configuration change.
<script src="https://auth.keyra.ie/sdk/keyra-oauth.js"></script>
<script>
KeyraOAuth.renderButton("#keyra-login", {
clientId: "cp_test_YOUR_PUBLISHABLE_KEY",
authOrigin: "https://auth.keyra.ie",
redirectUri: "https://YOUR_REGISTERED_CALLBACK/api/auth/keyra/callback",
scope: "verify",
mode: "popup",
appearance: { theme: "black", text: "login_with" }
});
</script>Never put a secret key (sk_test_ / sk_prod_) in browser examples. POST /oauth/token requires grant_type, code, redirect_uri, and code_verifier. redirect_uri must match the Keyra project callback.
