The three building blocks
The integration is built from three pieces that work together regardless of platform (Android, iOS, or web):How the SDK and APIs stitch together
TherequestId is the thread that ties every step together:
- Your server calls Create with the user’s identity and receives a
requestId. - Your server hands the
requestIdback to the client app. - The client app passes the
requestIdto the SDK viastart(). - The SDK performs the authentication with the OTPless Server and reports progress through callbacks.
- Independently, your server polls Status Check with the same
requestIdto determine the final, authoritative result.
Data flow
The flow is the same on every platform — only the SDK calls differ. The client app starts polling its own backend immediately after callingstart(requestId), while the SDK runs the authentication in parallel.
How to perform the status check
There are two ways to drive the Status Check API poll:Option 1: Poll right after start()
Option 1: Poll right after start()
Begin polling from your backend immediately after calling the SDK
start() method, and keep polling until you receive a terminal state (SUCCESS or FAILED).Always enforce a timeout threshold — if no terminal state is reached within that window, stop polling and mark the transaction as failed (timeout). This prevents the poll from running indefinitely if the flow never resolves.Option 2: Poll once after the SDK terminal callback (recommended)
Option 2: Poll once after the SDK terminal callback (recommended)
Wait for the SDK to emit a terminal callback (
ONETAP or AUTH_TERMINATED), and only then call the Status Check API once to fetch the final, authoritative status.This makes a single call instead of repeated polling, but it relies on the SDK callback being delivered to the client.Regardless of the approach, the Status Check API result from your server — not the SDK callback alone — is the source of truth for confirming a successful login.
SDK callback states
The SDK works in two steps, and each step has its own set of callbacks. First, the SDK must be initialized. Once initialization succeeds, you invoke thestart() method to begin authentication.
Step 1: Initialization callbacks
Emitted when you initialize the SDK.Step 2: Start callbacks
Emitted after you invokestart() to begin authentication.
The callbacks above describe the Android and iOS SDKs. The Web SDK
differs: authentication is started with
initiate() rather than start(),
readiness is read from isReady() instead of an SDK_READY callback, and
terminal failures arrive on FAILED instead of AUTH_TERMINATED. See the
Web SDK page.What to read next
Create API
Generate a
requestId from the user’s phone number or email.Android SDK
Initialize and start authentication on Android.
iOS SDK
Initialize and start authentication on iOS.
Web SDK
Initialize and initiate authentication on the web.
Status Check API
Poll the authoritative auth status from your server.