PortalAuth drives Portal’s Client Auth APIs and resolves a PortalSession that you pass to Portal(credentials:). It shares no state with Portal: it never touches wallets, MPC or signing, and your app owns all UI, redirect forwarding and wallet creation.
Initializer
authEnvironmentId: The Auth Environment ID from Authentication > Configure in the Portal dashboard. Sent as thex-portal-auth-environment-idheader on every request, and used as the Keychain key for the persisted session, so two instances built with the same ID share one session.redirectUrl: Where Portal sends the user once a magic link or provider sign-in completes. Must appear byte-for-byte on the environment’s Redirect URLs allow list and must match the URL scheme (or Universal Link) your app registers.signInWithGoogle/signInWithAppleadditionally require a custom scheme such asmyapp://auth/callback.apiHost: Optional Portal API host override.localhostand127.0.0.1usehttp://.magicLink: ThefromEmailandtemplateIdthatsendMagicLinkrequires. Omit it in an OAuth-only app.isAccountAbstracted: Whether the client Portal creates for a first-time user uses gas sponsorship. Omitted from every request whennil. Only takes effect on a user’s first sign-in.
PortalAuthError.invalidArgument(name:):authEnvironmentIdorredirectUrlis empty or blank. The initializer performs no network or Keychain I/O.
prefersEphemeralWebBrowserSession: Bool: Whentrue,signInWith*opens a browser sheet that does not share Safari’s cookies, so an existing Google or Apple sign-in is not reused. Defaults tofalse. Set it totrueto let a user who signed out pick a different account.setAuthPresentationAnchor(_ anchor: ASPresentationAnchor): The windowsignInWith*presents the browser sheet from. Held weakly. Required before callingsignInWithGoogleorsignInWithApple.
Types
PortalSession is a PortalCredentials: getToken() returns the Client Session Token until the session is invalidated, then throws PortalCredentialError.sessionInvalidated; invalidate() clears the in-memory token and deletes the persisted copy. endUserId is never secret and is the identifier to log and to key per-user state on.
Errors
PortalAuthError covers the authentication flow itself:
PortalAuthSignInError is specific to signInWithGoogle / signInWithApple. Its raw values are the Web SDK’s popup codes: closed (POPUP_CLOSED), unavailable (POPUP_UNAVAILABLE), signInInProgress (SIGN_IN_ALREADY_IN_PROGRESS) and callbackIncomplete (CALLBACK_INCOMPLETE).
Transport failures are not remapped. A 401 from any PortalAuth call surfaces as PortalRequestsError.unauthorized, unchanged; see Handle errors for what it means on each call.
Notes
- Hold one long-lived instance.
handleRedirectremembers the last grant it exchanged so a redirect delivered twice resolves to the same result; that memory lives on the instance. - The persisted session is stored in the Keychain with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly, keyed byauthEnvironmentId, in a namespace separate from wallet shares. It never syncs through iCloud Keychain, and it survives app deletion. - Available starting from SDK version 8.0.0.