Developer docs
Single sign-onPro and up
People arrive from your product already signed in.
If your product has accounts, people can arrive on the board already signed in as themselves, with their name and avatar. Your server signs a short token with the board's secret (board settings → Single sign-on) and sends the person to the board's SSO address.
The token
A JWT signed with HS256 and the board's secret, valid for at most 10 minutes.
| Claim | Description |
|---|---|
substringrequired | The person's id in your product. It's how we recognize them next time. |
emailstringrequired | Only the board's team sees it. |
expnumberrequired | Expiry, in seconds since 1970. At most 10 minutes ahead. |
namestring | Shown next to what they post. Up to 60 characters. |
avatarstring | An https image URL. |
metaobject | Up to 2 KB of flat key/values (plan, company, MRR…), shown to the team next to their posts. |
Node example
import { SignJWT } from "jose";
const secret = new TextEncoder().encode(process.env.FDBK_SSO_SECRET);
const token = await new SignJWT({ email: user.email, name: user.name, meta: { plan: user.plan } })
.setProtectedHeader({ alg: "HS256" })
.setSubject(String(user.id))
.setExpirationTime("5m")
.sign(secret);
// Link people here, or pass the token to the feedback button with data-sso-token.
const url = `https://fdbk.online/acme/app/sso?token=${token}&to=/acme/app/new`;to is optional and must be a page of the same board. Keep the secret on your server; if it leaks, rotate it in the board settings. With the feedback button, render the token with the page and pass it as data-sso-token. Single sign-on comes with Pro.