Customer Auth

Add signup and login to your own website without building authentication yourself. Drop in one snippet and your visitors can register, verify their email, sign in and reset passwords.

Overview

Customer Auth handles the sign-in flow for your end-users so you don't have to:

These end-users belong to your app's audience. They are separate from your SoftSolz workspace team members.

Enable the service

Open Marketplace in the sidebar, find Customer Auth and click Install. Once installed it appears in the sidebar. Open it and its two pages, End-users and Developer (for keys and the widget), are tabs under its name.

Set up your sending address before going live. The confirm-your-email and reset-your-password emails your users receive come from your own address, never from SoftSolz. Add one at Marketplace → Email sending. Until then, visitors see "This site cannot send email yet, so sign-up and password reset are not available right now." See Email sending.

Embed on your site

Open Customer Auth → Developer → Embed the widget. Under Public widget keys, enter your website address as the Allowed origin (for example https://example.com), click Generate key, and copy the key from the Save this key now window. The widget only loads on the addresses you allow.

Then paste this one line into any HTML page:

<script src="https://app.softsolz.uk/softsolz.js"
  data-service-id="customer-auth"
  data-public-key="pk_live_…"></script>

The widget renders the signup, login and reset-password screens. It resizes to fit your page automatically, so there is no build step.

Set your allowed domains before going live. If a domain isn't on the key's allowlist, the widget won't load there.

Four widgets, one key

Customer Auth gives you four separate widgets that all use the same key, so you can place each one wherever it belongs on your site or app:

The Embed snippets card gives you a ready-to-paste snippet for each one, using your most recent active key. The profile, 2FA and sign-out widgets need to know who is signed in, so they include a short note on how to hand them the logged-in session - your developer wires that up once.

Customise the look

In the Embed the widget panel you can match the widget to your brand and tune the sign-up experience, with a live preview as you edit:

These choices are saved with the key when you click Generate key. To change them later, click the pencil (Edit widget) on the key; sites using it pick up the change without a new snippet.

Sign-up asks for a name (optional), email, password and a password confirmation. After signing in, users can upload a profile photo from their account.

Where users appear

Open Customer Auth → End-users to see everyone who has signed up, with their status (Active, Pending verification or Suspended), last login and sign-up date. Search by email or name, or filter by status. Click a user to:

Use the API

Your own server can work with end-users through the API, with a secret key (sk_…):

WhatRequestScope
Check who a session token belongs to (call this from your backend after a visitor signs in) POST https://app.softsolz.uk/api/v1/services/customer-auth/sessions/verify with {"token": "…"} Verify sessions
List and search end-users GET https://app.softsolz.uk/api/v1/services/customer-auth/users Read end-users
Create, update or delete end-users POST, PATCH and DELETE on …/customer-auth/users Manage end-users

See the Customer Auth developer guide for the sign-in flow and every endpoint.

Test it step by step

Follow these steps once from start to finish to prove sign-up and sign-in work.

  1. Get access. You need the Super Admin or Admin role, or a custom role that includes the Customer Auth permissions (Members & access → Roles).
  2. Pick where to test. To keep test accounts out of your real user list, open the workspace menu and choose Switch to Sandbox mode. The sandbox has its own end-users, keys and settings.
  3. Install Customer Auth. Open Marketplace, find Customer Auth and click Install.
  4. Set up your sending address. Go to Marketplace → Email sending and add an address you own. This needs a real email account or domain. Do it in the workspace you are testing in, because live and sandbox each keep their own.
  5. Make a key for the Widget Tester. Go to Customer Auth → Developer → Embed the widget. Adjust the look if you like, then enter https://developer.softsolz.uk as the Allowed origin and click Generate key. Copy the key from the Save this key now window.
  6. Sign up in the Widget Tester. Open developer.softsolz.uk/widget-tester and choose Customer Auth. In the Embed snippet box, replace pk_live_REPLACE_WITH_YOUR_KEY with your key and click Load widget. Create an account with an inbox you can open. The widget says Check your inbox to confirm your email address.
  7. Confirm and sign in. Click the link in the email. A page opens saying Email verified. You can sign in now. Go back to the Widget Tester and sign in with the same email and password. The widget shows You are signed in.
  8. Check the user list. Open Customer Auth → End-users. Your test account is listed as Active with a last login time. Click it to see the session you just started.
  9. Put it on your own site. Generate a second key with your own website address as the allowed origin (the look is saved per key, so set it again first), copy the Sign in / Sign up snippet from Embed snippets, paste it into a page on your site and sign in once.
  10. Tidy up. Delete the test account, revoke keys you no longer need, and if you tested in the sandbox, switch back with Switch to Live mode to set up the real widget: sandbox users and keys never carry over.

For developers

In the sandbox, open Customer Auth → Developer → Use the API, click New API key and tick Read end-users. Sandbox keys start with sk_test_. Then look up your test account:

curl "https://app.softsolz.uk/api/v1/services/customer-auth/users?search=jane@example.com" \
  -H "Authorization: Bearer sk_test_your_key"

The reply lists matching end-users under data, with their status and when they verified their email. See the API Reference for filters and paging.

If something goes wrong

You seeWhat it means
Invalid embed key or origin not allowed. (inside the widget) The page address is not on the key's allowed origins, or the key was revoked. Generate a key for the exact address the page runs on, starting https:// with no path.
This site cannot send email yet, so sign-up and password reset are not available right now. No sending address is set up in this workspace. Add one at Marketplace → Email sending.
Confirm your email address first. We sent you a link when you signed up. The account has not clicked its confirmation link yet. Use Send the confirmation email again in the widget, and check the spam folder.
Invalid email or password. or Account is not active. The details are wrong, or the account was suspended or deleted. Check its status under Customer Auth → End-users.

Reference

Building a deeper integration? See the developer guide for endpoints and events: