Base URL: https://id.atlayo.com/api/
JavaScript SDK: https://id.atlayo.com/atlayo-id.js
Real-time updates: WebSocket at wss://atlayo.com:8443 (event join_identity_room)
Overview
Atlayo ID works like OAuth 2.0 for the Atlayo ecosystem. A website starts an auth session, the user approves it on their phone (QR scan or phone-number push), and the website receives scoped user data plus an access token.
- Authorize — website creates a session and shows QR code or phone form
- Approve — user reviews requested scopes in the Atlayo app and taps Allow
- Token — website exchanges the approved session for an access token
- Userinfo — optional: fetch user profile with Bearer token
Supported Scopes
Websites can request profile fields only. A per-site encrypted token is always returned automatically after login — it is not a scope.
| Scope | Description |
given_name | User first name |
family_name | User last name |
phone_number | Phone number (E.164 digits) |
gender | User gender (as stored in the Atlayo profile) |
language | App language — the language the user has set in the Atlayo app (e.g. en, cs) |
birthdate | Date of birth (YYYY-MM-DD) |
email | Email address |
User Token (auto-provided)
After approval, every login response includes a token field — an encrypted identifier unique to the user and your website domain. Use it on your backend to recognize returning users.
{
"given_name": "John",
"family_name": "Doe",
"phone_number": "420601123456",
"token": "xK9mP2...base64..."
}
Your backend resolves users with the site domain (or registered client domain) as the encryption key. The same user gets a different token on each website.
Start a new login session. Returns a QR payload and session token.
{
"client_id": "your_client_id",
"scopes": ["given_name", "family_name", "phone_number"],
"origin": "example.com",
"redirect_uri": "https://example.com/callback",
"state": "optional-csrf-token",
"login_method": "qr",
"clientGeo": { "country": "CZ", "city": "Prague" }
}
Response
{
"success": true,
"sessionToken": "abc123...",
"expiresAt": "2026-07-02 12:05:00",
"clientName": "My Website",
"requestedScopes": ["given_name", "family_name"],
"scopeLabels": ["First name", "Last name"],
"qrPayload": "{\"v\":1,\"t\":\"...\",\"sc\":[...]}",
"qrDeepLink": "atlayo://identity/..."
}
Attach a phone number to an existing session. Sends a login request to the user's Atlayo app.
{
"session_token": "abc123...",
"phone_number": "+420601123456"
}
Poll session status from the website. Returns loggedIn: true when the user approved on their phone.
Exchange an approved session for an access token. Public clients (browser SDK) send client_id + session_token only. Confidential clients also send client_secret.
{
"client_id": "your_client_id",
"session_token": "abc123..."
}
Response
{
"success": true,
"access_token": "....",
"token_type": "Bearer",
"expires_in": 300,
"user": {
"given_name": "John",
"family_name": "Doe",
"phone_number": "420601123456",
"token": "encrypted-site-specific-token"
},
"scopes": ["given_name", "family_name"]
}
Fetch user data with Authorization: Bearer <access_token>.
AtlayoID — client SDK
Include the SDK on any website to add "Login with Atlayo ID" with QR and phone flows.
<script src="https://cdn.socket.io/4.5.4/socket.io.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/qrcode-generator@1.4.4/qrcode.min.js"></script>
<script src="https://id.atlayo.com/atlayo-id.js"></script>
<div id="atlayo-qr"></div>
<input id="phone" type="tel" placeholder="+420 601 123 456">
<button id="phone-login">Login with phone</button>
<script>
const client = new AtlayoID({
clientId: 'your_client_id',
scopes: ['given_name', 'family_name', 'phone_number'],
onSuccess: (result) => {
console.log('User:', result.user);
console.log('Access token:', result.accessToken);
},
onError: (err) => alert(err.message)
});
// QR login
client.loginWithQR(document.getElementById('atlayo-qr'));
// Phone login
document.getElementById('phone-login').onclick = async () => {
await client.authorize({ loginMethod: 'phone' });
await client.loginWithPhone(document.getElementById('phone').value);
};
</script>
Call client.login() from a button click. If this browser was remembered after an earlier phone approval, Atlayo opens its own window, shows the current profile, and lists the data this site will receive. Nothing is shared until the user presses Continue. The website does not learn who is signed in until the user confirms. Each website still receives its own access token and its own site token.
document.getElementById("atlayo-login").onclick = () => client.login();
Remembering the browser is a checkbox on the approval screen in the Atlayo app. When it is checked, later sites that call login() can offer that same Atlayo ID. Inline loginWithQR() and phone login stay available for a different account.
AtlayoID.rememberedProfile({ clientId }) returns the remembered profile and the labels for your own HTML. It does not build the page. The labels cover the 24 official EU languages, follow the browser language, and fall back to English. Pass lang or labels to override any string.
const signIn = AtlayoID.rememberedProfile({ clientId: "your_client_id" });
if (!signIn) {
// The page is leaving to check this browser. It comes back on its own.
} else if (signIn.profile) {
continueButton.textContent = signIn.text("continueAs", { name: signIn.profile.displayName });
otherAccount.textContent = signIn.text("differentAccount");
continueButton.onclick = () => client.login({ autopick: true });
} else {
client.loginWithQR(document.getElementById("atlayo-qr"));
}
AtlayoID.mountRememberedLogin() can fill elements you already wrote. onResult runs after that, so you can still change the markup. AtlayoID.text("continueAs", { name }) and AtlayoID.text("differentAccount") return a single string.
QR Payload Format
The QR code contains compact JSON scanned by the Atlayo app:
{
"v": 1,
"s": 1,
"t": "session_token_hex",
"e": 1782070865,
"n": "Website Name",
"c": "client_id",
"sc": ["given_name", "family_name"],
"a": { "c": "CZ", "ci": "Prague", "q": "1.2.3.4" }
}
Deep link equivalent: atlayo://identity/<base64-json>