Authenticate Users Against The Borrower Platform
Use this guide when applicants already have an account in your product and you want to open the Borrower Platform for them without the email verification step. You generate a JWT for that user’s email, then pass the JWT when the Borrower Platform launches. The access token must stay on your server. It must never appear in public-facing code. If you only need a Borrower Platform link or embed snippet from the Lendflow Dashboard, go to Embed The Borrower Platform Into Your Product. To design welcome pages, tabs, and stage copy, go to Borrower Platform.Generate a JWT
Lendflow uses JWTs to authenticate users against the Borrower Platform. Generating a token for a user requires:- Your organization’s access token
- Your organization’s Borrower Platform token
- The email address of the user to authenticate
JSON
JSON
$.data.token path to the Borrower Platform in the next step.
Pass the JWT to the Borrower Platform
The Borrower Platform can start in three ways: as a standalone page (full-screen), as an overlay that covers the page and can be closed, or embedded as part of the page. Regardless of display mode, pass the JWT from the previous step as ajwt query string parameter during initialization. Also pass your organization’s Borrower Platform token as token.
Full-screen mode
Full-screen mode is a full-page redirect from your site to the Borrower Platform. At a minimum, the URL must contain:- The
jwtquery string parameter with the JWT generated above - The
tokenquery string parameter with your organization’s Borrower Platform token
https://borrower.lendflow.com?jwt={JWT}&token={borrower platform token}
Overlay and embedded modes
The samejwt and token query string parameters are required on the script embed. For example:
HTML
borrowerPlatform instance is attached to the current window global object. That instance has init and destroy methods.
Overlay mode
To run the Borrower Platform in overlay mode, passborrowerPlatform.init() as a callback on the element that should open it. For example:
HTML
postMessage events, "bp-initialize-borrower-platform" and "bp-close-borrower-platform", that correspond to the init and destroy methods. Besides working with the borrowerPlatform object, you can initialize or remove the Borrower Platform like this:
HTML
JavaScript
Embedded mode
To run the Borrower Platform as a section of a page, pass an additional query parametertarget on the integration script tag. That parameter is the id of an existing element in the DOM. The Borrower Platform replaces that placeholder after the script loads.
When target is present, the Borrower Platform initializes by itself. You do not have to call init. If target is present but an element with that id cannot be found, a BorrowerPlatformNoTargetElementError error is thrown.
HTML
FAQ
When do I use JWT login instead of the dashboard embed snippet?
When do I use JWT login instead of the dashboard embed snippet?
Use JWT login when the applicant is already signed in to your product and you want the Borrower Platform to open as that user. Use the snippet from the Integrations tab in the left-side menu, then Borrower Platform, when you are embedding without that handoff.
Can I put the access token in the Borrower Platform script on my website?
Can I put the access token in the Borrower Platform script on my website?
No. The access token is a secret. Request the JWT from your server, then pass only the JWT and the Borrower Platform token in the Borrower Platform script. Do not add them to a page URL.
Next steps
Embed The Borrower Platform Into Your Product
In the left-side menu, open the Integrations tab, then open Borrower Platform, and copy the link or integration script.
Borrower Platform
Create templates and customize the stages applicants see after they log in.