SDK Integration Guide
Simple 3-step setup for web developers
1. Declarative Config & Script Injection
Add the JSON configuration tag pointing to the /login endpoint and load the Korvali Auth Client SDK:
<script type="application/json" id="korvali-auth-config">
{
"origin": "https://auth.korvali.net/login",
"autoBind": false
}
</script>
<script src="https://auth.korvali.net/sdk.js"></script>
2. Execute Authentication & Native Decrypt
Invoke KorvaliAuth.login() to retrieve the raw encrypted payload, then execute Web Crypto API decryption on the client side:
document.getElementById('btnLogin').addEventListener('click', async () => {
try {
// SDK retrieves encrypted payload & challenge from auth.korvali.net
const session = await KorvaliAuth.login();
// Application decrypts the payload manually using the session challenge
const realId = await nativeDecrypt(session.payload, session.challenge);
console.log("Authenticated User Identity:", realId);
} catch (err) {
console.error("Authentication Canceled / Blocked:", err.message);
}
});
3. Check & Restore Active Session
// Check session on page load (Auto resets to STATE 0 if tab is duplicated or re-opened)
window.addEventListener('DOMContentLoaded', () => {
const activeSession = KorvaliAuth.getSession();
if (activeSession) {
// Session active in this tab
}
});