Frictionless Sign-in
Before you start: this flow requires an offlineToken for the customer. For new users, this is returned during Frictionless Sign-up →. For existing users without one, generate it using the Reset Offline Token → endpoint.
Before you start:This flow requires an offlineToken for the customer. For new users, this is returned during Frictionless Sign-up →. For existing users without one, generate it using the Reset Offline Token → endpoint.
Good to know:
offlineTokencan be re-used indefinitely as it does not expire.
refreshTokenexpires after 24 hours. A new one must be obtained to authenticate the customer anew.
Token overview
| Token | Expires | Purpose |
|---|---|---|
offlineToken | Never | Stored on your server; used to generate a refreshToken per session |
refreshToken | 24 hours | Passed to the Trade Widget to authenticate the user |
accessToken | 20 minutes | Used for direct API calls on behalf of the user |
Step 1 — Exchange the offline token for a refresh token
Call the Offline Token Sign-in → endpoint with the customer's offlineToken:
{
"grant_type": "offline_token",
"offline_token": "OzjLekdEzKQSDuMFpXm6dcLU1hTj1LsC2I+5a6DMm3Kq6XNjqc4694wimeI8UKN7" //not a valid token, just an example
}{
"access_token": "eyJhbGciOiJFUzI5NiIsInR5cCI6IkpXVCJ9.eyJpYXQiOjE2OTY0OTA2NjgsImV4cCI6MTY5NjQ5MEk2OCwidWlkIjo2NzY4OCwiZXYiOmZhbHNlLCJzYyI6eyJ0XzIyMjI0IjoiKiJ9fQ.a7xi7-A1il0yDFdPamPl8q4mQValrWkeyrid5EAPzqD2WygSNC4f519pqgSH-jg5Vtmk0EtWsfRbL8jS33pIdw",
"token_type": "bearer",
"expires_in": 1200,
"refresh_token": "zR5PAGj0uPLzOP5Cgeo5ofEmAR/j2b3uRviSmH54eHfe+ZQ/PPvLoeqTT61Mv9nw"
}This call should happen server-side on each new session — the refreshToken is valid for 24 hours.
Step 2 — Pass the refresh token to the Trade Widget
Pass the refreshToken value to the widget. The user is automatically signed in and lands directly on the Buy or Sell screen, bypassing the Coinify sign-in page entirely.
Trade Widget (iframe)
URL-encode the refreshToken value before appending it to the iframe URL:
<!DOCTYPE html>
<html>
<body>
<h2>Trade Widget Example</h2>
<p>You can use the height and width attributes to specify the size of the iframe:</p>
<iframe src="https://trade-ui.sandbox.coinify.com?partnerId=your-partner-id&refreshToken=xR5PAGj0uPLzOP5Cgeo5ofEmAR%2Fj2b3uRviSmH54cHfe%2BZQ%2FPPvJoeqTT61Mv9nw" width="100%" height="700px" allow="camera;fullscreen;accelerometer;gyroscope;magnetometer" allowfullscreen></iframe>
</body>
</html>
Always URL-encode the refreshToken before appending it to the widget URL — special characters in the token value will break the URL if passed unencoded.
Trade Widget SDK
Pass it directly as a JavaScript string — no URL encoding needed:
Coinify.Trade({ partnerId: 'your-partner-id', partnerName: 'Your App' })
.render({
containerId: 'coinify-widget',
parameters: {
refreshToken: 'xR5PAGj0uPLzOP5Cgeo5ofEmAR/j2b3uRviSmH54cHfe+ZQ/PPvJoeqTT61Mv9nw',
targetPage: 'buy',
noMenu: true
}
});Trade Widget Example
You can use the height and width attributes to specify the size of the iframe:
Next steps
Mandatory User Information → — what the end-user must provide before they can trade
Trade Widget → — full list of supported query parameters including refreshToken
Authentication Methods → — overview of all sign-in options including password and refresh token flows
Updated about 2 hours ago
