Customer Auth
Add signup and login to your own website without building authentication yourself. Drop in one snippet and your visitors can register, verify their email, sign in and reset passwords.
Overview
Customer Auth handles the sign-in flow for your end-users so you don't have to:
- Visitors register with an email and password.
- They confirm their email, then log in.
- They can reset a forgotten password on their own.
- You see every end-user in your dashboard and can manage them.
Enable the service
Open Marketplace in the sidebar, find Customer Auth and click Install. Once installed it appears in the sidebar. Open it and its two pages, End-users and Developer (for keys and the widget), are tabs under its name.
Embed on your site
Open Customer Auth → Developer → Embed the widget. Under Public widget keys, enter your website address as the Allowed origin (for example https://example.com), click Generate key, and copy the key from the Save this key now window. The widget only loads on the addresses you allow.
Then paste this one line into any HTML page:
<script src="https://app.softsolz.uk/softsolz.js"
data-service-id="customer-auth"
data-public-key="pk_live_…"></script>
The widget renders the signup, login and reset-password screens. It resizes to fit your page automatically, so there is no build step.
Four widgets, one key
Customer Auth gives you four separate widgets that all use the same key, so you can place each one wherever it belongs on your site or app:
- Sign in / Sign up - the login and registration flow (this is the default).
- Profile - lets a signed-in user edit their name and upload a photo. Drop it on your account page.
- Two-factor authentication - lets a signed-in user turn 2FA on or off. Drop it in your security settings.
- Sign-out button - a logout button you can place in your header or menu.
The Embed snippets card gives you a ready-to-paste snippet for each one, using your most recent active key. The profile, 2FA and sign-out widgets need to know who is signed in, so they include a short note on how to hand them the logged-in session - your developer wires that up once.
Customise the look
In the Embed the widget panel you can match the widget to your brand and tune the sign-up experience, with a live preview as you edit:
- Colours, fonts and corners for the whole widget.
- Logo position - left, right or centred, or hide the header.
- Headings for the sign-in and sign-up screens.
- Require two-factor authentication - off by default. When on, end-users must set up an authenticator app before they can finish signing in.
- Redirects - the page to send people to After login and After logout.
- Enforce password requirements - off by default (a minimum of 8 characters). Turn it on to set minimum characters and numbers, and to require an uppercase letter or a special character. Visitors see a live checklist as they type.
- Custom messages - optional helper text on the sign-in form, the sign-up form, the forgot-password form and the new-password screen.
These choices are saved with the key when you click Generate key. To change them later, click the pencil (Edit widget) on the key; sites using it pick up the change without a new snippet.
Sign-up asks for a name (optional), email, password and a password confirmation. After signing in, users can upload a profile photo from their account.
Where users appear
Open Customer Auth → End-users to see everyone who has signed up, with their status (Active, Pending verification or Suspended), last login and sign-up date. Search by email or name, or filter by status. Click a user to:
- View their profile, active sessions and session history.
- Suspend them to block sign-in, and Reactivate them later.
- Force logout to end every active session.
- Disable 2FA if they have lost their authenticator.
- Delete them entirely.
Use the API
Your own server can work with end-users through the API, with a secret key (sk_…):
| What | Request | Scope |
|---|---|---|
| Check who a session token belongs to (call this from your backend after a visitor signs in) | POST https://app.softsolz.uk/api/v1/services/customer-auth/sessions/verify with {"token": "…"} |
Verify sessions |
| List and search end-users | GET https://app.softsolz.uk/api/v1/services/customer-auth/users |
Read end-users |
| Create, update or delete end-users | POST, PATCH and DELETE on …/customer-auth/users |
Manage end-users |
See the Customer Auth developer guide for the sign-in flow and every endpoint.
Test it step by step
Follow these steps once from start to finish to prove sign-up and sign-in work.
- Get access. You need the Super Admin or Admin role, or a custom role that includes the Customer Auth permissions (Members & access → Roles).
- Pick where to test. To keep test accounts out of your real user list, open the workspace menu and choose Switch to Sandbox mode. The sandbox has its own end-users, keys and settings.
- Install Customer Auth. Open Marketplace, find Customer Auth and click Install.
- Set up your sending address. Go to Marketplace → Email sending and add an address you own. This needs a real email account or domain. Do it in the workspace you are testing in, because live and sandbox each keep their own.
- Make a key for the Widget Tester. Go to Customer Auth → Developer → Embed the widget. Adjust the look if you like, then enter
https://developer.softsolz.ukas the Allowed origin and click Generate key. Copy the key from the Save this key now window. - Sign up in the Widget Tester. Open developer.softsolz.uk/widget-tester and choose Customer Auth. In the Embed snippet box, replace
pk_live_REPLACE_WITH_YOUR_KEYwith your key and click Load widget. Create an account with an inbox you can open. The widget says Check your inbox to confirm your email address. - Confirm and sign in. Click the link in the email. A page opens saying Email verified. You can sign in now. Go back to the Widget Tester and sign in with the same email and password. The widget shows You are signed in.
- Check the user list. Open Customer Auth → End-users. Your test account is listed as Active with a last login time. Click it to see the session you just started.
- Put it on your own site. Generate a second key with your own website address as the allowed origin (the look is saved per key, so set it again first), copy the Sign in / Sign up snippet from Embed snippets, paste it into a page on your site and sign in once.
- Tidy up. Delete the test account, revoke keys you no longer need, and if you tested in the sandbox, switch back with Switch to Live mode to set up the real widget: sandbox users and keys never carry over.
For developers
In the sandbox, open Customer Auth → Developer → Use the API, click New API key and tick Read end-users. Sandbox keys start with sk_test_. Then look up your test account:
curl "https://app.softsolz.uk/api/v1/services/customer-auth/users?search=jane@example.com" \
-H "Authorization: Bearer sk_test_your_key"
The reply lists matching end-users under data, with their status and when they verified their email. See the API Reference for filters and paging.
If something goes wrong
| You see | What it means |
|---|---|
| Invalid embed key or origin not allowed. (inside the widget) | The page address is not on the key's allowed origins, or the key was revoked. Generate a key for the exact address the page runs on, starting https:// with no path. |
| This site cannot send email yet, so sign-up and password reset are not available right now. | No sending address is set up in this workspace. Add one at Marketplace → Email sending. |
| Confirm your email address first. We sent you a link when you signed up. | The account has not clicked its confirmation link yet. Use Send the confirmation email again in the widget, and check the spam folder. |
| Invalid email or password. or Account is not active. | The details are wrong, or the account was suspended or deleted. Check its status under Customer Auth → End-users. |
Reference
Building a deeper integration? See the developer guide for endpoints and events: