Skip to content

Authentication and sessions

In the usual Reskyt model, the identity system and the login remain those of the client’s ecommerce. The app does not maintain its own identity system or a parallel user base: it shows the authentication flow inside the WebView.

The capabilities in this section are modules and integrations that are incorporated when they are part of the project scope. None of them is included by default.

Biometrics. Biometric login stores credentials using the operating system’s secure storage and allows signing in with Face ID, Touch ID or fingerprint instead of typing them.

Social login. The Facebook Login and Google Sign-In modules enable native sign-in with those providers.

Device identification. The uuid_app cookie identifies the installation and allows it to be linked to a profile in your database, which makes it possible to keep the session open between app launches.

The session is kept with the same mechanisms as on your website (cookies and browser storage), but inside the app container.

If your store already uses SSO or OAuth, the flow runs inside the app just as it does on the web. Flows that open an external browser and return to the app require review during project setup.

AreaResponsible
Identity system and user baseYour ecommerce
Login, registration and recovery flowYour ecommerce
Password policy and session expiryYour ecommerce
Biometric layer and native social login, when integratedReskyt
Form selectors for biometricsConfigured by Reskyt on your website
Changes to the login flowYour team, notifying Reskyt

If the login form changes, the biometrics configuration may stop recognising it. Redesigns should be communicated in advance.