Skip to main content
Class Definition
PortalAuth drives Portal’s Client Auth APIs and resolves a PortalSession that you pass to Portal(credentials:). It shares no state with Portal: it never touches wallets, MPC or signing, and your app owns all UI, redirect forwarding and wallet creation. Initializer
Parameters
  • authEnvironmentId: The Auth Environment ID from Authentication > Configure in the Portal dashboard. Sent as the x-portal-auth-environment-id header on every request, and used as the Keychain key for the persisted session, so two instances built with the same ID share one session.
  • redirectUrl: Where Portal sends the user once a magic link or provider sign-in completes. Must appear byte-for-byte on the environment’s Redirect URLs allow list and must match the URL scheme (or Universal Link) your app registers. signInWithGoogle / signInWithApple additionally require a custom scheme such as myapp://auth/callback.
  • apiHost: Optional Portal API host override. localhost and 127.0.0.1 use http://.
  • magicLink: The fromEmail and templateId that sendMagicLink requires. Omit it in an OAuth-only app.
  • isAccountAbstracted: Whether the client Portal creates for a first-time user uses gas sponsorship. Omitted from every request when nil. Only takes effect on a user’s first sign-in.
Throws
  • PortalAuthError.invalidArgument(name:): authEnvironmentId or redirectUrl is empty or blank. The initializer performs no network or Keychain I/O.
Properties and configuration
  • prefersEphemeralWebBrowserSession: Bool: When true, signInWith* opens a browser sheet that does not share Safari’s cookies, so an existing Google or Apple sign-in is not reused. Defaults to false. Set it to true to let a user who signed out pick a different account.
  • setAuthPresentationAnchor(_ anchor: ASPresentationAnchor): The window signInWith* presents the browser sheet from. Held weakly. Required before calling signInWithGoogle or signInWithApple.
Methods Types
PortalSession is a PortalCredentials: getToken() returns the Client Session Token until the session is invalidated, then throws PortalCredentialError.sessionInvalidated; invalidate() clears the in-memory token and deletes the persisted copy. endUserId is never secret and is the identifier to log and to key per-user state on. Errors PortalAuthError covers the authentication flow itself: PortalAuthSignInError is specific to signInWithGoogle / signInWithApple. Its raw values are the Web SDK’s popup codes: closed (POPUP_CLOSED), unavailable (POPUP_UNAVAILABLE), signInInProgress (SIGN_IN_ALREADY_IN_PROGRESS) and callbackIncomplete (CALLBACK_INCOMPLETE). Transport failures are not remapped. A 401 from any PortalAuth call surfaces as PortalRequestsError.unauthorized, unchanged; see Handle errors for what it means on each call. Notes
  • Hold one long-lived instance. handleRedirect remembers the last grant it exchanged so a redirect delivered twice resolves to the same result; that memory lives on the instance.
  • The persisted session is stored in the Keychain with kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly, keyed by authEnvironmentId, in a namespace separate from wallet shares. It never syncs through iCloud Keychain, and it survives app deletion.
  • Available starting from SDK version 8.0.0.
Example Usage
Related Documentation