Create
Create an Embeddable Magic Link token for a User.
Documentation Index
Fetch the complete documentation index at: https://stytch.com/docs/llms.txt
Use this file to discover all available pages before exploring further.
Important usage notes
Carefully review the following notes before using Embeddable Magic Links:- Embeddable Magic Link tokens are sensitive values. You should handle and store them securely.
- Authenticating an Embeddable Magic Link token will not mark any of a user’s delivery factors (email address or phone number) as verified, since we cannot confirm how the token was sent to the user.
- Embeddable Magic Links are only available in our Consumer API, and not our B2B API.
- Deliverability is paramount. Carefully test your email copy to ensure it reaches your users’ inboxes. Small changes can result in your emails being sent to spam.
- In some cases, email security bots may follow links within incoming emails before your users open them. This consumes the Embeddable Magic Link token, preventing the user from logging in when they later click the link. Our Email Magic Links product automatically prevents this (details here). However, when sending your own emails containing Embeddable Magic Links, you’ll be responsible for detecting and stopping bot traffic using tools like CAPTCHA or Device Fingerprinting.
Authorizations
Basic authentication header of the form Basic <encoded-value>, where <encoded-value> is the base64-encoded string username:password.
Body
Request type
The unique ID of a specific User. You may use an external_id here if one is set for the user.
Set the expiration for the Magic Link token in minutes. By default, it expires in 1 hour. The minimum expiration is 5 minutes and the maximum is 7 days (10080 mins).
Provided attributes to help with fraud detection. These values are pulled and passed into Stytch endpoints by your application.
Response
Successful response
Globally unique UUID that is returned with every API call. This value is important to log for debugging purposes; we may ask for this value to help identify a specific API call when helping you debug an issue.
The unique ID of the affected User.
The Magic Link token that you'll include in your contact method of choice, e.g. email or SMS.
The HTTP status code of the response. Stytch follows standard HTTP response status code patterns, e.g. 2XX values equate to success, 3XX values are redirects, 4XX are client errors, and 5XX are server errors.