What you just built
A real app authenticating against a hosted Seamless Auth instance: passwordless sign-in, a server-side security boundary, and a portal to manage users, roles, plans, and tokens. No auth infrastructure to operate.
This guide takes you from signing up on the Seamless Auth portal to a real app where a user can sign in, using a hosted auth instance that Seamless runs for you. You do not run a database, signing keys, or an auth server on this path.
If you would rather run the whole stack yourself, follow the Self-Hosted Quickstart instead. Not sure which path fits? See Managed or Self-Hosted.
npm is used below)Open the Seamless Auth portal at https://dashboard.seamlessauth.com and sign up.
The portal is itself passwordless and built on Seamless Auth, so there is no password to choose:
You now have a portal account. The portal is where you create applications, manage plans and billing, generate service tokens, and watch users and auth events for each application.
An application is one hosted auth instance. From the dashboard, choose Create your first application (or New Application) and fill in the form.
Basic fields:
https://...)Advanced fields are optional and have safe defaults. They include notification email(s), application roles and default role, a development-mode toggle, AWS region, access and refresh token TTLs, and rate-limit thresholds.
| Plan | Price | Notes |
|---|---|---|
| Trial | Free | 14 days, no credit card required |
| MVP | $49 / mo | |
| Business | $99 / mo | Recommended for most new products |
| Enterprise | Contact sales | Not self-serve, email support@seamlessauth.com |
For a paid plan, the portal sends you through Stripe checkout before provisioning. On the Trial plan, provisioning starts immediately.
After you submit, Seamless provisions the instance. This takes a few minutes (the portal estimates about five). When it finishes, the application has its own Auth Server URL of the form:
https://<your-app-id>.seamlessauth.comThis URL is what your SDKs point at. You can find it on the application’s Auth API Configuration card at any time.
Your backend authenticates to the hosted auth instance with a service token. Generate it from the application’s Auth API Configuration card:
The full token is shown once. Copy it immediately and store it as a server-side secret. The portal keeps only a masked copy (the last few characters) for reference, so it cannot show you the full value again.
The service token is a long, URL-safe secret. Your backend reads it from an environment variable
(shown as SEAMLESS_SERVICE_TOKEN below); the frontend never sees it.
Install the React SDK in your frontend project:
npm install @seamless-auth/reactWrap your app in AuthProvider, using your application’s Auth Server URL as apiHost, then read
session state with useAuth():
import { AuthProvider, useAuth } from '@seamless-auth/react';
const AUTH_URL = 'https://<your-app-id>.seamlessauth.com';
export function App() { return ( <AuthProvider apiHost={AUTH_URL}> <AppRoutes /> </AuthProvider> );}
function AppRoutes() { const { isAuthenticated, user } = useAuth();
return isAuthenticated ? <p>Signed in as {user?.email}</p> : <LoginPage />;}AuthProvider takes only apiHost (required) and an optional autoDetectPreviousSignin. There is no
frontend token or client id: the browser SDK carries no secret and relies on cookies. For built-in
sign-in screens, mount AuthRoutes; for custom UI, use the headless client. See the
React SDK reference for the full API.
Install the Express SDK in your backend project:
npm install @seamless-auth/expressMount the auth server and read the service token from a server-side environment variable. Point
authServerUrl and audience at the same Auth Server URL as the frontend:
import express from 'express';import createSeamlessAuthServer from '@seamless-auth/express';
const AUTH_URL = 'https://<your-app-id>.seamlessauth.com';
const app = express();
app.use( '/auth', createSeamlessAuthServer({ authServerUrl: AUTH_URL, cookieSecret: process.env.COOKIE_SIGNING_KEY!, serviceSecret: process.env.SEAMLESS_SERVICE_TOKEN!, // from the portal, shown once jwksKid: process.env.JWKS_KID!, issuer: process.env.APP_ORIGIN!, audience: AUTH_URL, }),);Set these environment variables on your backend:
| Variable | Value |
|---|---|
SEAMLESS_SERVICE_TOKEN | The service token generated in Step 3 |
COOKIE_SIGNING_KEY | A strong random secret your backend uses to sign its auth cookies |
JWKS_KID | The signing key id for your instance |
APP_ORIGIN | Your backend’s own origin, used as the token issuer |
The service token is never sent raw. The adapter uses it to sign short-lived service tokens for
machine-to-machine calls to your hosted instance. To protect routes, add requireAuth and
requireRole from the same package. See the Server SDKs reference for the full
option list and middleware.
Run your frontend and backend, then sign in:
useAuth() reports the user as authenticated.Back in the portal, the new account appears on the application’s Users page once it authenticates, and the sign-in shows up under Auth Events. Here you can manage users and roles. This is the managed-path equivalent of role editing.
What you just built
A real app authenticating against a hosted Seamless Auth instance: passwordless sign-in, a server-side security boundary, and a portal to manage users, roles, plans, and tokens. No auth infrastructure to operate.
| You need to | Go to |
|---|---|
| Copy your Auth Server URL | Application → Auth API Configuration card |
| Generate or rotate the token | Application → Auth API Configuration → Service Token |
| See users and their sign-ins | Application → Users, Application → Auth Events |
| Change or upgrade your plan | Application → Billing |
| Re-run the connection steps | Application → Get connected |