Skip to content

Commit 2a3483b

Browse files
authored
Merge pull request #1880 from codatio/update/secure-linking-getting-started
Update "How to get started" on the secure linking update
2 parents 24e4bf7 + 0379e15 commit 2a3483b

1 file changed

Lines changed: 11 additions & 2 deletions

File tree

‎blog/250110-secure-linking.md‎

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,10 @@ All clients who want to have stricter rules around Link URLs sent to their custo
3030

3131
## How to get started?
3232

33-
Contact your Codat account manager with the request to enable one-time Link URLs. Depending on the type of the Link flow you are using, you also need to action the following:
33+
To set up one-time Link URLs:
34+
35+
1. **Enable the One-time Link URLs setting** in the [Codat Portal](https://app.codat.io) under **[Settings > Auth flow > Link > Onboarding](https://app.codat.io/settings/link-settings/onboarding)**.
36+
2. **Complete the additional steps for your Link flow**, as described below.
3437

3538
#### If using Hosted Link
3639

@@ -42,4 +45,10 @@ If you are currently adding query parameters to Link URLs (for example, by appen
4245

4346
#### If using Link SDK
4447

45-
To enforce the limited validity of Link URLs using the Link SDK, you need to retrieve an access token for your customer using the [Get company access token](/platform-api#/operations/get-company-access-token) endpoint and pass it when initializing the SDK. This serves as an equivalent to a one-time password appended to a Link URL.
48+
The Link SDK uses an access token instead of an appended one-time password. To set this up:
49+
50+
1. **Register your domain** using the [Set CORS settings](/platform-api#/operations/set-cors-settings) endpoint so the component can make authenticated requests from your site.
51+
2. **Get a company access token.** Retrieve it server-side from the [Get company access token](/platform-api#/operations/get-company-access-token) endpoint (`GET /companies/{companyId}/accessToken`). Tokens are valid for 24 hours and scoped to a single company.
52+
3. **Pass the token to the Link SDK** via the `accessToken` prop when initializing the component.
53+
54+
Reach out to your account manager or our support team if you'd like help getting set up.

0 commit comments

Comments
 (0)