Skip to main content

Authenticate Users Against The Borrower Platform

Use this guide when applicants already have an account in your product and you want to open the Borrower Platform for them without the email verification step. You generate a JWT for that user’s email, then pass the JWT when the Borrower Platform launches. The access token must stay on your server. It must never appear in public-facing code. If you only need a Borrower Platform link or embed snippet from the Lendflow Dashboard, go to Embed The Borrower Platform Into Your Product. To design welcome pages, tabs, and stage copy, go to Borrower Platform.

Generate a JWT

Lendflow uses JWTs to authenticate users against the Borrower Platform. Generating a token for a user requires:
  • Your organization’s access token
  • Your organization’s Borrower Platform token
  • The email address of the user to authenticate
The access token is a secret which should never appear in public-facing code.
Send this request to Lendflow, including headers, request method, endpoint, and body:
JSON
A successful response contains the JWT in this format:
JSON
Pass the JWT at the $.data.token path to the Borrower Platform in the next step.

Pass the JWT to the Borrower Platform

The Borrower Platform can start in three ways: as a standalone page (full-screen), as an overlay that covers the page and can be closed, or embedded as part of the page. Regardless of display mode, pass the JWT from the previous step as a jwt query string parameter during initialization. Also pass your organization’s Borrower Platform token as token.

Full-screen mode

Full-screen mode is a full-page redirect from your site to the Borrower Platform. At a minimum, the URL must contain:
  • The jwt query string parameter with the JWT generated above
  • The token query string parameter with your organization’s Borrower Platform token
For example: https://borrower.lendflow.com?jwt={JWT}&token={borrower platform token}

Overlay and embedded modes

The same jwt and token query string parameters are required on the script embed. For example:
HTML
After that script loads, a borrowerPlatform instance is attached to the current window global object. That instance has init and destroy methods.

Overlay mode

To run the Borrower Platform in overlay mode, pass borrowerPlatform.init() as a callback on the element that should open it. For example:
HTML
The Borrower Platform instance also listens for two custom postMessage events, "bp-initialize-borrower-platform" and "bp-close-borrower-platform", that correspond to the init and destroy methods. Besides working with the borrowerPlatform object, you can initialize or remove the Borrower Platform like this:
HTML
JavaScript

Embedded mode

To run the Borrower Platform as a section of a page, pass an additional query parameter target on the integration script tag. That parameter is the id of an existing element in the DOM. The Borrower Platform replaces that placeholder after the script loads. When target is present, the Borrower Platform initializes by itself. You do not have to call init. If target is present but an element with that id cannot be found, a BorrowerPlatformNoTargetElementError error is thrown.
HTML

FAQ

Use JWT login when the applicant is already signed in to your product and you want the Borrower Platform to open as that user. Use the snippet from the Integrations tab in the left-side menu, then Borrower Platform, when you are embedding without that handoff.
No. The access token is a secret. Request the JWT from your server, then pass only the JWT and the Borrower Platform token in the Borrower Platform script. Do not add them to a page URL.

Next steps

Embed The Borrower Platform Into Your Product

In the left-side menu, open the Integrations tab, then open Borrower Platform, and copy the link or integration script.

Borrower Platform

Create templates and customize the stages applicants see after they log in.