Skip to main content
Profile Portal exposes the login endpoints its own pages use, so a brand website or app that owns the login form can trigger the same magic link email, email code, or SMS code and finish the login itself. The customer never has to see a Profile Portal page unless you want them to. This is different from the External app magic link, which builds the emailed link on your own app URL and needs a bearer token and a shared secret. The endpoints on this page are the public ones behind the Profile Portal login screen: no credentials, but rate limited and, for browser calls, restricted to allow-listed origins.

Before you start

How the code flow works

1

Your site requests a code

The customer enters their email address or mobile number on your site. Your site calls POST /api/auth/email-code or POST /api/auth/sms.
2

Omneo sends the code

When the profile exists, Omneo issues a 6-digit code and sends it using your configured email template or SMS sender. Nothing is sent for an unknown contact.
3

Your site verifies the code

The customer enters the code on your site. Your site calls POST /api/auth/code/verify with the code and the same email address or mobile number.
4

Omneo returns an ID token

Omneo checks the code, invalidates it, and returns a profile-scoped Omneo ID token. Use it to open Profile Portal already logged in, or call the Omneo ID service directly. See Use the token.
Emails the customer a magic link that opens Profile Portal already logged in. The link is valid for about 24 hours.

Body

Other fields accepted by this endpoint are used by Profile Portal’s own pages and are not needed from an external site.

Responses

identity is the customer’s loyalty card number when your tenant has a loyalty card identity configured, otherwise false.

Send a login code by email

Body

Responses

Send a login code by SMS

Body

Responses

Verify a code

Verifies a code from either channel. Send the same identifier the code was requested with.

Body

Responses

POST /api/auth/sms/retrieve is a legacy alias of this endpoint with the same body and responses. Use /api/auth/code/verify for new integrations.

Use the token

The token returned by verify is the same value Profile Portal puts in its own magic links, so you have two options. Open Profile Portal logged in. Redirect the customer to the portal’s login route with the token and an optional path:
Stay on your site. Base64-decode the token to get the JWT, read its pid (profile ID) and exp (unix expiry) claims, and use the JWT as a bearer token against the Omneo ID service, for example GET https://api.[tenant].getomneo.com/id/api/v1/profiles/me. The steps are the same as validating the ID token on app open. The token is short-lived; to refresh it, mint a new one server-side as described in Using Omneo ID.

Code behaviour

Example

The first call returns type: "existing", the second returns { "data": { "token": "<base64-jwt>", "id": "<profile-id>" } }, and repeating the second call returns 400 because the code has been used.