Overview
Connect an external website to AccessGuard through the server-side bridge proxy and browser SDK using scoped HMAC v2 credentials and canonical customer-safe operations.
Capabilities
-
Registration, login, token refresh, recovery, reset, logout, introspection, and email/phone verification
-
Profile management, profile data, protected profile media, and profile upload operations
-
Customer notification inbox counts, list, read, seen, delete, pin, and unpin
-
Audience read operations and ContextResolver operations when explicitly granted
-
Client credential administration with origins, operations/scopes, rate limits, request logging, rotation, replay protection, and status
Setup Steps (4)
-
1
Step 1
Create a site credential in AccessGuard and define the allowed origin, operations, scopes, and rate limit.
-
2
Step 2
Configure the server-side bridge proxy with the client ID, client secret, and AccessGuard Bridge endpoint.
-
3
-
4
Step 4
Run a signed health/authentication request and verify the Bridge request log and authorization state.
Limitations
-
The client secret remains on the trusted server side of the external website integration.
-
Bridge authority is limited to the credential, workspace, operation, scope, origin, rate, and request-signature policy configured for that client.
FAQs
How are website requests authenticated?
The site-side bridge proxy signs canonical requests with HMAC v2 using the configured client ID and secret.
Can a website use profile and notification operations after login?
Yes. AccessGuard exposes customer-safe profile, protected media, and notification inbox capabilities through Bridge when the client is granted those operations and scopes.
Pricing
Starter
USD 365.17 / annual
Pro
USD 1,095.66 / annual
Enterprise
USD 2,921.89 / annual