PortalAuth method. Completes a sign-in that handleRedirect or signInWith* left at .totpRequired. On success the session is saved to the Keychain before it is returned.
Parameters
code: The six-digit code from the user’s authenticator app. Posted exactly as given, with no trimming or length check, so validate the input before submitting.userJwt: TheuserJwtfrom theTotpRequiredResult, passed back verbatim. Short-lived (ten minutes) and never persisted by the SDK.
AuthenticatedResult: Contains the following:session:PortalSession, already persisted. Pass it toPortal(credentials:).clientId:String?, the Portal Client this session belongs to.isAccountAbstracted:Bool?, whether that client uses gas sponsorship.
PortalAuthError.invalidUserJwt(detail:):userJwtcannot be read (for example it is blank or carries noendUserId). Raised before the network call, so a bad JWT never costs the user a live code. Restart the sign-in.PortalRequestsError.unauthorized: The code was wrong, or theuserJwthas expired or already been used. The SDK cannot tell which. A wrong code does not consume the JWT, so let the user try again with the sameTotpRequiredResult; if that keeps failing, start a new sign-in.PortalAuthError.malformedResponse(path:missing:): The response carried noclientSessionToken.PortalAuthError.sessionStorageFailure(message:): The code was accepted but the session could not be saved to the Keychain. CallverifyTotpagain with the sameuserJwt: the SDK finishes the write and returns the session without a network call.- Other transport errors unchanged.
TotpRequiredResult.totpLink carries an otpauth:// URI the user needs to enroll an authenticator app. The SDK provides:
totpSecret is nil, and qrCodeImage throws PortalAuthError.totpQrUnavailable, when totpLink is missing, is not an otpauth:// URI, or carries no valid secret. totpLink is nil for a user who is already enrolled.
Notes
- Nothing is persisted until
verifyTotpsucceeds. If the JWT expires or the app is killed first, the user signs in again from the beginning. - The
endUserIdof the resulting session is read from theuserJwt; the TOTP endpoint does not return it. - After success, a redirect re-delivered for the same grant replays as this
.authenticatedresult rather than the TOTP step. - Never log or persist
userJwt,totpLinkortotpSecret;totpLinkembeds the TOTP secret.TotpRequiredResultredacts both fromdescriptionanddump, so printing the value itself is safe. If you offer a “Copy key” button, useUIPasteboard.general.setItems(_:options:)with.localOnly: trueand a short.expirationDate. - A user who loses their authenticator can be reset from the dashboard; see End users.
- Available starting from SDK version 8.0.0.