Sign-in & session
Users sign in to your application with their Secrecy account, on the hosted Secrecy sign-in page. Your application never sees a password, and never has to store one. What it gets back is a session and the user's keys, and from them a ready-to-use SecrecyClient.
Sign-in is when the keys reach the device
In a zero-knowledge service, a session alone is not enough: the client also needs private keys to decrypt anything. Secrecy only stores those keys locked, and only the Secrecy sign-in page can unlock them, with the user's master key. Sign-in is the moment the unlocked keys — the user's identity in your application, and the groups they belong to — are delivered to the device, together with the session and the JWT of your application. The master key itself stays on the sign-in page.
That is why every call that reads or writes encrypted data needs a signed-in client, and why a client is always tied to one user of one application.
How sign-in works
- Your application calls
loginwith its app id, and optionally the scopes it asks for, such as the user's email. - The user is sent to the Secrecy sign-in page, in a popup or with a full-page redirect, and signs in there.
- The sign-in page unlocks the user's keys and sends them back to your application with the session, and the SDK builds the client.
If a client is already stored for this browser, login returns it directly, without showing the sign-in page again.
The session lives in the browser
After sign-in, the SDK keeps the session and the keys in the browser, so the user does not sign in again on every page load. On the next load, getSecrecyClient rebuilds the client from what was stored, and logout ends the session and wipes the stored keys.
The unlocked keys are never sent back to the Secrecy servers. What is stored, and how to keep it for the current tab only, is detailed in session and storage.
When no sign-in is needed
Two features work without a client, on purpose: downloading a link and encrypting anonymously. Their users have no Secrecy account, so they get standalone functions instead.
To implement sign-in, see Secrecy auth.