Docs

Guide: identifying logged-in users

Let the browser, app or hosted preference center act for a signed-in person — safely — with identity tokens.

A publishable key (pk_) lives in your page or app, so anyone can copy it. On its own it can only reach anonymous visitors — the device id the CMP and SDKs mint. To read or write a signed-in person (email:, external_id:, phone:, custom:) from the browser or an app, the request also carries an identity token: a short-lived signed statement from your backend that says "this visitor is external_id:u_42".

Without a token, those calls return 403 identity_token_required. Anonymous device ids keep working exactly as before, and secret (sk_) keys are never affected.

1. Create an identity secret

Console → Integrate → Identity tokens → Create identity secret (admins only). Copy the isec_… secret and its id (kid) into your server config, like an sk_ key. You can have two active secrets at once to rotate without downtime; revoking one invalidates every token signed with it immediately.

2. Sign a token on your server after login

import { signIdentityToken } from '@tripticonsent/sdk/server';

const identityToken = await signIdentityToken({
  secret: process.env.TC_IDENTITY_SECRET,   // isec_…
  secretId: process.env.TC_IDENTITY_KID,
  siteId: process.env.TC_SITE_ID,
  subject: `external_id:${user.id}`,     // prefer a stable id over an email
  // ttlSeconds: 3600 (default), max 24 h
});

Not on Node? It's a standard HS256 JWT: header { "alg": "HS256", "typ": "JWT", "kid": "<secret id>" }, payload { "sub": "external_id:u_42", "site": "<site id>", "aud": "tripticonsent:identity", "iat": <now>, "exp": <now + ≤ 86400> }, signed with the secret. Any JWT library works.

3. Pass it along

  • Cookie banner (CMP): cmp.identify('external_id:u_42', identityToken) right after login, or data-tc-subject + data-tc-identity-token on the script tag of a server-rendered page. On logout: cmp.identify(cmp.getDeviceId()).
  • JavaScript SDK: new TripticonsentClient({ apiKey: 'pk_live_…', identityToken }) or tc.setIdentityToken(token).
  • iOS / Android / Flutter: the identityToken option or setIdentityToken(…). The app's key must have Allow native apps enabled — apps send no Origin header.
  • Raw API: send it as the X-Tc-Identity header.
  • WordPress plugin: no code — Settings → Tripticonsent → Logged-in visitors. The plugin signs the token server-side and the banner fetches it from an uncached endpoint, so cached pages never carry anyone's token. Other CMSs can do the same with the CMP's data-tc-identity-endpoint (a same-origin URL returning { subject, identityToken, expiresIn }, or 204 when logged out).

The hosted preference center takes the token in the link, so only the recipient can open it: sign with use: 'prefs' (up to 30 days) and link to https://tripticonsent.tripticode.com/en/prefs?pk=<pk_…>&it=<token>. An expired or tampered link shows a "link expired" page.

const it = await signIdentityToken({ ...config, subject: `external_id:${user.id}`, use: 'prefs', ttlSeconds: 14 * 86400 });
Keep tokens short-lived and never put the secret in client code. A token only ever vouches for the one person in its sub — it can't reach anybody else, and it is bound to your site.