WiraPass adds a second step when people sign in to your system. Once the password checks out, the user approves the sign-in on their phone, or types a backup code from the WiraPass app.
How WiraPass Fits into a Sign-In
- The user types an email and password into your system, and your system checks them as usual. WiraPass never sees that password.
- Your system asks WiraPass whether this user can be asked for approval (
preauth). Users are identified by the email they use in WiraPass. - WiraPass sends a request to the user's approval phones that are signed in to the WiraPass app (
auth). The screen shows the name of your system, the title of the request and the details you send, such as the IP address. - The user taps Approve, Deny or Not me. Approve is signed by the device key on the phone, so it cannot be forged from outside. Not me also pauses new requests from your system for that user for 15 minutes.
- Your system reads the result (
auth_status) and lets the user in only when it isallow.
When the phone has no internet connection, the user opens the WiraPass app and reads the 6-digit backup code. Your system checks it with factor=passcode. Each code works only once.
Two APIs, One Approval System
Both follow the same rules: requests only go to phones signed in to WiraPass, at most 3 waiting requests per user, and a 15-minute pause after Not me. One integration may use both APIs.
Getting Integration Keys
For now, integration keys are created by the WiraPass operator. Email support@wiracode.com with:
- the name of your system, exactly as users should see it on their phone (at most 80 characters);
- a technical contact;
- a rough number of users and requests per minute.
You will receive:
| Value | Format | For |
|---|---|---|
| Integration key (ikey) | DI and 18 upper-case letters or digits | Auth API |
| Secret key (skey) | 40 letters and digits | Auth API |
| API hostname | auth.wiracode.com | Auth API |
| Simple API key | wpk_… | Simple JSON API |
The secret key and the API key are shown only once. Keep them like passwords, on your server, never in a web page or a mobile app. If one leaks, ask for a new one: the old one stops working at once.
Next Steps
OpenAPI Specification
Both APIs are described in one OpenAPI 3.1 document at https://auth.wiracode.com/openapi.json. You can open it in Swagger Editor, Postman or a client generator.