Embedded login
Embedded login opens Cortecloud screens already authenticated for a user of your system, without them typing a username and password. Your backend asks the API for an access URL and hands it to the user, who opens it in the browser.
There are two routes, one for each type of user:
| Route | User | Screen opened |
|---|---|---|
POST /embed/quick-service | Service center salesperson | Registration of a new service for a carpenter. |
POST /embed/service | Carpenter | The service center's whitelabel: its site inside Cortecloud, with its branding. |
Both routes use the same authentication as the others and respond with 201 and the URL:
{ "url": "https://..." }
Handling the URL
- The URL is valid for a single access and expires in 60 seconds. Generate it when the user is about to open it, not before.
- The URL grants access to the user's account. Hand it only to that user, and do not log or store it.
- The API call is made by your backend, which holds the secret key. The browser receives only the URL.
New service for a salesperson
Route: POST /embed/quick-service.
The URL opens Cortecloud authenticated as the given salesperson, on the screen for registering a new service for the given carpenter, to be produced on the given production line.
| Field | Description |
|---|---|
companyInternalCode | Service center code. It must match the x-company-internal-code header; otherwise, the response is 401. |
productionInternalCode | Internal code of the production line where the parts will be produced. |
sellerEmail | Email of the salesperson who will receive the access. |
sellerName | Salesperson's name. |
carpenterEmail | Email of the carpenter the service will be created for. |
carpenterName | Carpenter's name. |
carpenterInternalCode | Code that identifies the carpenter in your system. |
All fields are required.
Before generating the URL, the route registers the salesperson in the service center and the carpenter in Cortecloud, if they don't exist yet, and links the carpenter to the service center with the code carpenterInternalCode. Repeating the call with the same data doesn't create duplicate records. Two cases need attention:
- if the carpenter already has an active link with the service center, the internal code they already have is kept, and
carpenterInternalCodedoes not replace it; - if the salesperson is registered in another service center, they are moved to the request's service center and lose the link with the previous one.
{
"companyInternalCode": "CENTRAL-SP",
"productionInternalCode": "LINHA-1",
"sellerEmail": "vendedor@example.com",
"sellerName": "Fulano Vendedor",
"carpenterEmail": "marceneiro@example.com",
"carpenterName": "Beltrano Marceneiro",
"carpenterInternalCode": "CLI-0042"
}
Carpenter area
Route: POST /embed/service.
The URL opens the whitelabel of the request's service center (x-company-internal-code) authenticated as the given carpenter. The carpenter is registered in Cortecloud if they don't exist yet.
| Field | Description |
|---|---|
carpenterEmail | Email of the carpenter who will receive the access. |
carpenterName | Carpenter's name. |
Both fields are required.
{
"carpenterEmail": "marceneiro@example.com",
"carpenterName": "Beltrano Marceneiro"
}
Errors
| Status | Situation |
|---|---|
400 | A required field is missing, a field is empty or an email is invalid. |
401 | Authentication failure or, in quick-service, companyInternalCode different from x-company-internal-code. |
404 | In /embed/service: the service center has no whitelabel configured. |
409 | The given email already belongs to a user with another profile, for example a salesperson's email sent as a carpenter. |
429 | The integration exceeded the request limit. |
5xx or another status | Failure to register the users or to generate the access; the message carries the reason. It may be transient: retry with increasing backoff and a limited number of attempts, and write to suporte@serrabits.com.br if it persists. |