Docs menu
Enabling Single Sign-on
Sign your users in to the editor automatically.
Your users are already signed in to your site. Single sign-on (SSO) carries that into the editor, so they never see a GNR AI sign-in. The SDK needs it: the editor opens only with a valid token.
How it works
- Your user signs in to your site.
- Your server makes a short token naming them, signed with your SSO key.
- Your page passes it to
initializeasembedToken.
The first time a user arrives, they get their own GNR AI account and brand, listed under yours as a team member.
Your SSO key
Go to Brand & Accounts → API & SDK and copy the SSO key.
⚠ Caution
Keep the SSO key on your server. Anyone who has it can sign in as any of your users. If it leaks, press Make a new SSO key; tokens signed with the old one stop working at once.
Making the token
The token is a JWT signed with HS256 and your SSO key.
import jwt, time
token = jwt.encode(
{"aud": YOUR_APP_ID, "user_id": USER_ID, "exp": int(time.time()) + 3600},
SSO_KEY,
algorithm="HS256",
)import jwt from "jsonwebtoken";
const token = jwt.sign({ aud: APP_ID, user_id: userId }, SSO_KEY, {
algorithm: "HS256",
expiresIn: "1h",
});The payload
| Field | Type | Required | Meaning |
|---|---|---|---|
aud | String | Yes | Your App ID. |
user_id | String | Yes | Your own id for the user — an email or any unique id. The same id always opens the same account. |
exp | Number | Recommended | Expiry, in seconds since 1970. Expired tokens are refused. |
About security
The token carries only the App ID and your id for the user — no password, encoded or otherwise. GNR AI checks the signature against your SSO key and refuses anything else. It is passed from your page to our frame with postMessage, never in a web address, and the editor only accepts it from the websites you listed.