Skip to content

Send email link

Request

Send a magic link by email to a user. Upon clicking the email link, the User Agent will be redirected to the requested redirect URI with a code (passed in the code query parameter). This code can be used to complete the authentication in the subsequent request.

Security
ClientAccessToken
Bodyapplication/jsonrequired
One of:
device_idstring, <= 80 characters

Identifier of the device from which the authentication request originates

redirect_uristringrequired

URI that receives a code when the user clicks the email link. This is your server GET endpoint used to complete the authentication, and should accept 'code' as a query parameter. This URI must be configured as an allowed redirect URI for your Transmit client.

Example:"https://www.example.com/verify"
email_contentobject

Texts, logo and color to render email template with

statestring

An opaque string that is used to maintain state between the request and the callback. It will be added to the redirect URI as a query parameter, which should be validated by your server to protect against cross-site request forgery (CSRF) attacks

email_expirationnumber

invitation link expiration in minutes

channelstring

Channel to use to send the magic link

Enum:"email""direct"
client_attributesobject

Client attributes

generate_request_idboolean

The request ID can serve as an additional security identifier for authentication requests. When set to 'false' (by default), the request ID isn't returned. When set to 'true', Mosaic generates a unique request ID that must be included in the subsequent Authenticate OTP request along with other required parameters.

Default:false
identifierstringrequired

Identifier value (email, phone number, user ID, or custom identifier)

Example:"name@example.com"
identifier_typestringrequired

Type of identifier (email, phone_number, user_id, username, or custom identifier type)

Example:"email"
curl -i -X POST \
  https://api.sbx.transmitsecurity.io/cis/v1/auth/link/email/send \
  -H 'Authorization: Bearer <YOUR_TOKEN_HERE>' \
  -H 'Content-Type: application/json' \
  -d '{
    "device_id": "string",
    "redirect_uri": "https://www.example.com/verify",
    "email_content": {
      "subject": "string",
      "primaryColor": "#6981FF",
      "base64logo": "string",
      "headerText": "string",
      "bodyText": "string",
      "linkText": "string",
      "infoText": "string",
      "footerText": "If you didn'\''t request this email, you can safely ignore it.",
      "senderName": "string"
    },
    "state": "string",
    "email_expiration": 0,
    "channel": "email",
    "client_attributes": {
      "user_agent": "string",
      "ip_address": "string"
    },
    "generate_request_id": false,
    "identifier": "name@example.com",
    "identifier_type": "email"
  }'

Responses

Backend auth initialized successfully.

Bodyapplication/json
messagestringrequired
Example:"Email sent successfully"
Response
{ "message": "Email sent successfully" }