Skip to content

Identity verification ​

Without verification, any page that has your public key can call identify("someone-else") and write to that person's profile. Identity verification stops this. Your server signs each user id, and JustOneCX rejects calls without a valid signature.

Turn it on ​

  1. Open Settings → Developers → Identity verification.
  2. Enable it and copy the identity secret.
  3. Store the secret on your server only. Never put it in client code.

Sign on your server ​

js
// Node.js, server only
import { createHmac } from "node:crypto";

const userHash = createHmac("sha256", process.env.JUSTONECX_IDENTITY_SECRET)
  .update(user.id)
  .digest("hex");

Send userHash to the browser with the signed-in user, for example in your session payload.

Pass it to the SDK ​

ts
identify(user.id, { plan: user.plan }, { userHash });
group(account.id, { plan: account.plan }, { accountHash });

accountHash is the HMAC of the account id, computed the same way.

What happens without a valid hash ​

When verification is on, a call without a valid hash returns normally but is ignored. It cannot merge into another person's profile or change their traits.

Rotating the secret ​

Rotating the secret invalidates every hash you issued. Deploy the new secret to your server first, then rotate in the dashboard.

JustOneCX