Guide: identifying logged-in users
Let the browser, app or hosted preference center act for a signed-in person — safely — with identity tokens.
A publishable key (pk_) lives in your page or app, so anyone can copy it. On its own it can only reach anonymous visitors — the device id the CMP and SDKs mint. To read or write a signed-in person (email:, external_id:, phone:, custom:) from the browser or an app, the request also carries an identity token: a short-lived signed statement from your backend that says "this visitor is external_id:u_42".
403 identity_token_required. Anonymous device ids keep working exactly as before, and secret (sk_) keys are never affected.1. Create an identity secret
Console → Integrate → Identity tokens → Create identity secret (admins only). Copy the isec_… secret and its id (kid) into your server config, like an sk_ key. You can have two active secrets at once to rotate without downtime; revoking one invalidates every token signed with it immediately.
2. Sign a token on your server after login
import { signIdentityToken } from '@tripticonsent/sdk/server';
const identityToken = await signIdentityToken({
secret: process.env.TC_IDENTITY_SECRET, // isec_…
secretId: process.env.TC_IDENTITY_KID,
siteId: process.env.TC_SITE_ID,
subject: `external_id:${user.id}`, // prefer a stable id over an email
// ttlSeconds: 3600 (default), max 24 h
});Not on Node? It's a standard HS256 JWT: header { "alg": "HS256", "typ": "JWT", "kid": "<secret id>" }, payload { "sub": "external_id:u_42", "site": "<site id>", "aud": "tripticonsent:identity", "iat": <now>, "exp": <now + ≤ 86400> }, signed with the secret. Any JWT library works.
3. Pass it along
- Cookie banner (CMP):
cmp.identify('external_id:u_42', identityToken)right after login, ordata-tc-subject+data-tc-identity-tokenon the script tag of a server-rendered page. On logout:cmp.identify(cmp.getDeviceId()). - JavaScript SDK:
new TripticonsentClient({ apiKey: 'pk_live_…', identityToken })ortc.setIdentityToken(token). - iOS / Android / Flutter: the
identityTokenoption orsetIdentityToken(…). The app's key must have Allow native apps enabled — apps send noOriginheader. - Raw API: send it as the
X-Tc-Identityheader. - WordPress plugin: no code — Settings → Tripticonsent → Logged-in visitors. The plugin signs the token server-side and the banner fetches it from an uncached endpoint, so cached pages never carry anyone's token. Other CMSs can do the same with the CMP's
data-tc-identity-endpoint(a same-origin URL returning{ subject, identityToken, expiresIn }, or204when logged out).
Emailed preference-center links
The hosted preference center takes the token in the link, so only the recipient can open it: sign with use: 'prefs' (up to 30 days) and link to https://tripticonsent.tripticode.com/en/prefs?pk=<pk_…>&it=<token>. An expired or tampered link shows a "link expired" page.
const it = await signIdentityToken({ ...config, subject: `external_id:${user.id}`, use: 'prefs', ttlSeconds: 14 * 86400 });sub — it can't reach anybody else, and it is bound to your site.