Skip to main content

Embedded login

Embedded login opens Cortecloud screens already authenticated for a user of your system, without them typing a username and password. Your backend asks the API for an access URL and hands it to the user, who opens it in the browser.

There are two routes, one for each type of user:

RouteUserScreen opened
POST /embed/quick-serviceService center salespersonRegistration of a new service for a carpenter.
POST /embed/serviceCarpenterThe service center's whitelabel: its site inside Cortecloud, with its branding.

Both routes use the same authentication as the others and respond with 201 and the URL:

{ "url": "https://..." }

Handling the URL​

  • The URL is valid for a single access and expires in 60 seconds. Generate it when the user is about to open it, not before.
  • The URL grants access to the user's account. Hand it only to that user, and do not log or store it.
  • The API call is made by your backend, which holds the secret key. The browser receives only the URL.

New service for a salesperson​

Route: POST /embed/quick-service.

The URL opens Cortecloud authenticated as the given salesperson, on the screen for registering a new service for the given carpenter, to be produced on the given production line.

FieldDescription
companyInternalCodeService center code. It must match the x-company-internal-code header; otherwise, the response is 401.
productionInternalCodeInternal code of the production line where the parts will be produced.
sellerEmailEmail of the salesperson who will receive the access.
sellerNameSalesperson's name.
carpenterEmailEmail of the carpenter the service will be created for.
carpenterNameCarpenter's name.
carpenterInternalCodeCode that identifies the carpenter in your system.

All fields are required.

Before generating the URL, the route registers the salesperson in the service center and the carpenter in Cortecloud, if they don't exist yet, and links the carpenter to the service center with the code carpenterInternalCode. Repeating the call with the same data doesn't create duplicate records. Two cases need attention:

  • if the carpenter already has an active link with the service center, the internal code they already have is kept, and carpenterInternalCode does not replace it;
  • if the salesperson is registered in another service center, they are moved to the request's service center and lose the link with the previous one.
{
"companyInternalCode": "CENTRAL-SP",
"productionInternalCode": "LINHA-1",
"sellerEmail": "vendedor@example.com",
"sellerName": "Fulano Vendedor",
"carpenterEmail": "marceneiro@example.com",
"carpenterName": "Beltrano Marceneiro",
"carpenterInternalCode": "CLI-0042"
}

Carpenter area​

Route: POST /embed/service.

The URL opens the whitelabel of the request's service center (x-company-internal-code) authenticated as the given carpenter. The carpenter is registered in Cortecloud if they don't exist yet.

FieldDescription
carpenterEmailEmail of the carpenter who will receive the access.
carpenterNameCarpenter's name.

Both fields are required.

{
"carpenterEmail": "marceneiro@example.com",
"carpenterName": "Beltrano Marceneiro"
}

Errors​

StatusSituation
400A required field is missing, a field is empty or an email is invalid.
401Authentication failure or, in quick-service, companyInternalCode different from x-company-internal-code.
404In /embed/service: the service center has no whitelabel configured.
409The given email already belongs to a user with another profile, for example a salesperson's email sent as a carpenter.
429The integration exceeded the request limit.
5xx or another statusFailure to register the users or to generate the access; the message carries the reason. It may be transient: retry with increasing backoff and a limited number of attempts, and write to suporte@serrabits.com.br if it persists.