> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lendflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authenticate Users Against The Borrower Platform

## Authenticate Users Against The Borrower Platform

Use this guide when applicants already have an account in **your** product and you want to open the Borrower Platform for them without the email verification step.

You generate a JWT for that user’s email, then pass the JWT when the Borrower Platform launches. The access token must stay on your server. It must never appear in public-facing code.

If you only need a Borrower Platform link or embed snippet from the Lendflow Dashboard, go to [Embed The Borrower Platform Into Your Product](/lendflow-external/docs/embed-the-borrower-platform-into-your-landing-page). To design welcome pages, tabs, and stage copy, go to [Borrower Platform](/lendflow-external/docs/borrower-platform).

## Generate a JWT

Lendflow uses JWTs to authenticate users against the Borrower Platform. Generating a token for a user requires:

* Your organization’s access token
* Your organization’s Borrower Platform token
* The email address of the user to authenticate

<Warning>
  The access token is a secret which should never appear in public-facing code.
</Warning>

Send this request to Lendflow, including headers, request method, endpoint, and body:

```json JSON theme={"system"}
Authorization: Bearer {access token}
Borrower-Platform-Client-Token: {borrower platform token}

POST /borrower_platform/auth/client

{
  "email": "jason@example.com"
}
```

A successful response contains the JWT in this format:

```json JSON theme={"system"}
{
    "data": {
        "token": "JWT here..."
    }
}
```

Pass the JWT at the `$.data.token` path to the Borrower Platform in the next step.

## Pass the JWT to the Borrower Platform

The Borrower Platform can start in three ways: as a standalone page (full-screen), as an overlay that covers the page and can be closed, or embedded as part of the page.

Regardless of display mode, pass the JWT from the previous step as a `jwt` query string parameter during initialization. Also pass your organization’s Borrower Platform token as `token`.

### Full-screen mode

Full-screen mode is a full-page redirect from your site to the Borrower Platform. At a minimum, the URL must contain:

* The `jwt` query string parameter with the JWT generated above
* The `token` query string parameter with your organization’s Borrower Platform token

For example: `https://borrower.lendflow.com?jwt={JWT}&token={borrower platform token}`

### Overlay and embedded modes

The same `jwt` and `token` query string parameters are required on the script embed. For example:

```html HTML theme={"system"}
<script defer src="https://borrower.lendflow.com/lfbp.js?jwt={JWT}&token={borrower platform token}"></script>
```

After that script loads, a `borrowerPlatform` instance is attached to the current `window` global object. That instance has `init` and `destroy` methods.

### Overlay mode

To run the Borrower Platform in overlay mode, pass `borrowerPlatform.init()` as a callback on the element that should open it. For example:

```html HTML theme={"system"}
<button onclick="borrowerPlatform.init()">
  Start Borrower Platform
</button>
```

The Borrower Platform instance also listens for two custom `postMessage` events, `"bp-initialize-borrower-platform"` and `"bp-close-borrower-platform"`, that correspond to the `init` and `destroy` methods. Besides working with the `borrowerPlatform` object, you can initialize or remove the Borrower Platform like this:

```html HTML theme={"system"}
<button onclick="myCustomFunction()">Confirm</button>
```

```js JavaScript theme={"system"}
function myCustomFunction() {
  const openBp = confirm("Do you want to open BP?");
  if (openBp) {
    window.postMessage({ eventName: "bp-initialize-borrower-platform" }, "*");
  }
}
```

### Embedded mode

To run the Borrower Platform as a section of a page, pass an additional query parameter `target` on the integration script tag. That parameter is the id of an existing element in the DOM. The Borrower Platform replaces that placeholder after the script loads.

When `target` is present, the Borrower Platform initializes by itself. You do not have to call `init`. If `target` is present but an element with that id cannot be found, a `BorrowerPlatformNoTargetElementError` error is thrown.

```html HTML theme={"system"}
<html>
  <head>
    <script defer src="https://borrower.lendflow.com/lfbp.js?jwt={JWT_HERE}&token={PLATFORM_TOKEN_HERE}&target={TARGET_ELEMENT_ID_HERE}"></script>
  </head>
  <body>
    <p>Estibulum et enim vestibulum, consectetur felis sit amet, faucibus tellus</p>
    <div id="{TARGET_ELEMENT_ID_HERE}"></div>
  </body>
</html>
```

## FAQ

<AccordionGroup>
  <Accordion title="When do I use JWT login instead of the dashboard embed snippet?">
    Use JWT login when the applicant is already signed in to your product and you want the Borrower Platform to open as that user. Use the snippet from the **Integrations** tab in the left-side menu, then **Borrower Platform**, when you are embedding without that handoff.
  </Accordion>

  <Accordion title="Can I put the access token in the Borrower Platform script on my website?">
    No. The access token is a secret. Request the JWT from your server, then pass only the JWT and the Borrower Platform token in the Borrower Platform script. Do not add them to a page URL.
  </Accordion>
</AccordionGroup>

## Next steps

<Card title="Embed The Borrower Platform Into Your Product" icon="browser" href="/lendflow-external/docs/embed-the-borrower-platform-into-your-landing-page" horizontal>
  In the left-side menu, open the Integrations tab, then open Borrower Platform, and copy the link or integration script.
</Card>

<Card title="Borrower Platform" icon="table" href="/lendflow-external/docs/borrower-platform" horizontal>
  Create templates and customize the stages applicants see after they log in.
</Card>
