Choose an authentication flow
Find the right GOFA credential and guide for your integration.
GOFA uses different credentials for member sign-in, client administration, and
Commercial API requests. Choose the flow for the operation you need; the
credentials are not interchangeable.
- Flutter Lessons or WebView member sign-in: Start with
SDK authentication. Existing releases use a
legacy app-held client secret. The planned replacement keeps its SSO key on
your backend and returns a Firebase custom token to the app.
- Client administration from a backend: Use
Client tokens for
/api/client operations. Exchange a client secret and use the ClientToken
on your backend only.
- Commercial APIs from a backend: Use
Commercial API authentication for hosted services
such as Vital Scan. Send the Commercial API key from your backend only.
- Existing GOFA password or Firebase sign-in: Use
User authentication. A Firebase
custom token signs the user in; the resulting ID token identifies the user
to protected routes.
The SDK's existing client-secret sign-in is a legacy mobile integration.
A secret supplied to a Flutter build or bundled into an app can be extracted
from the distributed package. See SDK authentication
for its current status and the planned server-mediated migration.