Hosted login gives your app a Viresso-managed passwordless login page. It is useful when you want user authentication without building the login, verification, and redirect screens yourself.
Hosted login is based on a content type in your workspace that contains an email field. A person can sign in when their email exists in that content type.
Before You Start
- Create or choose the content type that represents your app users.
- Make sure that content type has an email field named
email. - Go to Settings → Authentication.
- Enable authentication and select the content bucket and content type that contain your users.
Turn On Hosted Login
- Go to Settings → Hosted Login.
- Turn on Status.
- Set the browser origin that is allowed to use hosted login.
- Set the redirect URL that Viresso sends users back to. It must use the allowed origin.
- Adjust the hosted page colors if needed.
- Save changes.
Login URL
The hosted login page is available at:
/@your-workspace/auth/login
You may include a state query parameter when opening the login page. Viresso returns that opaque value unchanged with the authorization code, so your app can restore its own return path or verify request state. The destination itself is always the redirect URL configured in Settings → Hosted Login.
Allowed Origin
The allowed origin limits which browser origin may use hosted login and hosted-auth API endpoints. Enter the exact origin including its scheme and port when needed, for example https://app.example.com.
Requests with an Origin header that does not match the configured origin are rejected with 403 Forbidden. Server-side requests that do not send an Origin header are not blocked by this browser-origin check.
Redirect URL
The configured redirect URL protects users by ensuring Viresso always sends them back to one known callback on the allowed origin. After verification, Viresso appends the short-lived authorization code and optional state while preserving any query string or fragment already configured on the URL.
Appearance
You can set the background, button, and text colors for hosted login and verification pages. Keep the page recognizable to your users, but avoid colors that make the form difficult to read.
Related Pages
- Authentication Settings - Choose the content type used for authentication.
- API Authentication - Use hosted authentication with your app.
- API Access - Create API keys for programmatic API access.