Frictionless Sign-in

Before you start: this flow requires an offlineToken for the customer. For new users, this is returned during Frictionless Sign-up →. For existing users without one, generate it using the Reset Offline Token → endpoint.

ℹ️

Before you start:

This flow requires an offlineToken for the customer. For new users, this is returned during Frictionless Sign-up →. For existing users without one, generate it using the Reset Offline Token → endpoint.

📘

Good to know:

offlineToken can be re-used indefinitely as it does not expire.

refreshToken expires after 24 hours. A new one must be obtained to authenticate the customer anew.

Token overview

TokenExpiresPurpose
offlineTokenNeverStored on your server; used to generate a refreshToken per session
refreshToken24 hoursPassed to the Trade Widget to authenticate the user
accessToken20 minutesUsed for direct API calls on behalf of the user

Step 1 — Exchange the offline token for a refresh token

Call the Offline Token Sign-in → endpoint with the customer's offlineToken:

{
  "grant_type": "offline_token",
  "offline_token": "OzjLekdEzKQSDuMFpXm6dcLU1hTj1LsC2I+5a6DMm3Kq6XNjqc4694wimeI8UKN7" //not a valid token, just an example
 }
{
  "access_token": "eyJhbGciOiJFUzI5NiIsInR5cCI6IkpXVCJ9.eyJpYXQiOjE2OTY0OTA2NjgsImV4cCI6MTY5NjQ5MEk2OCwidWlkIjo2NzY4OCwiZXYiOmZhbHNlLCJzYyI6eyJ0XzIyMjI0IjoiKiJ9fQ.a7xi7-A1il0yDFdPamPl8q4mQValrWkeyrid5EAPzqD2WygSNC4f519pqgSH-jg5Vtmk0EtWsfRbL8jS33pIdw",
  "token_type": "bearer",
  "expires_in": 1200,
  "refresh_token": "zR5PAGj0uPLzOP5Cgeo5ofEmAR/j2b3uRviSmH54eHfe+ZQ/PPvLoeqTT61Mv9nw"
}

This call should happen server-side on each new session — the refreshToken is valid for 24 hours.

Step 2 — Pass the refresh token to the Trade Widget

Pass the refreshToken value to the widget. The user is automatically signed in and lands directly on the Buy or Sell screen, bypassing the Coinify sign-in page entirely.

Trade Widget (iframe)

URL-encode the refreshToken value before appending it to the iframe URL:

<!DOCTYPE html>
<html>
<body>
<h2>Trade Widget Example</h2>
<p>You can use the height and width attributes to specify the size of the iframe:</p>

<iframe src="https://trade-ui.sandbox.coinify.com?partnerId=your-partner-id&refreshToken=xR5PAGj0uPLzOP5Cgeo5ofEmAR%2Fj2b3uRviSmH54cHfe%2BZQ%2FPPvJoeqTT61Mv9nw" width="100%" height="700px" allow="camera;fullscreen;accelerometer;gyroscope;magnetometer" allowfullscreen></iframe>
</body>
</html>
📘

Always URL-encode the refreshToken before appending it to the widget URL — special characters in the token value will break the URL if passed unencoded.

Trade Widget SDK

Pass it directly as a JavaScript string — no URL encoding needed:

Coinify.Trade({ partnerId: 'your-partner-id', partnerName: 'Your App' })
  .render({
    containerId: 'coinify-widget',
    parameters: {
      refreshToken: 'xR5PAGj0uPLzOP5Cgeo5ofEmAR/j2b3uRviSmH54cHfe+ZQ/PPvJoeqTT61Mv9nw',
      targetPage: 'buy',
      noMenu: true
    }
  });

Trade Widget Example

You can use the height and width attributes to specify the size of the iframe:


Next steps

Mandatory User Information → — what the end-user must provide before they can trade
Trade Widget → — full list of supported query parameters including refreshToken
Authentication Methods → — overview of all sign-in options including password and refresh token flows



Did this page help you?