Appearance
Identity verification
Without verification, any page that has your public key can call identify("someone-else") and write to that person's profile. Identity verification stops this. Your server signs each user id, and JustOneCX rejects calls without a valid signature.
Turn it on
- Open Settings → Developers → Identity verification.
- Enable it and copy the identity secret.
- Store the secret on your server only. Never put it in client code.
Sign on your server
js
// Node.js, server only
import { createHmac } from "node:crypto";
const userHash = createHmac("sha256", process.env.JUSTONECX_IDENTITY_SECRET)
.update(user.id)
.digest("hex");Send userHash to the browser with the signed-in user, for example in your session payload.
Pass it to the SDK
ts
identify(user.id, { plan: user.plan }, { userHash });
group(account.id, { plan: account.plan }, { accountHash });accountHash is the HMAC of the account id, computed the same way.
What happens without a valid hash
When verification is on, a call without a valid hash returns normally but is ignored. It cannot merge into another person's profile or change their traits.
Rotating the secret
Rotating the secret invalidates every hash you issued. Deploy the new secret to your server first, then rotate in the dashboard.