> For a complete page index, fetch https://docs.transak.com/llms.txt
# Auth Reliance
**Auth Reliance** allows partners to authenticate users without requiring them to re-login into the Transak authentication flow. This feature is exclusively available for [Whitelabel API integrations](/integration/api).
## Watch: How Auth Reliance Works
A short walkthrough of Auth Reliance and how it lets partners pass authenticated users into Transak's flow without a second login.
## Problem Statement
Integrating third-party payment services often forces users to create separate accounts and log in multiple times, disrupting the user experience and increasing friction in the conversion funnel.
Here are some of the **key challenges** with traditional authentication flows in payment integrations:
|
**Redundant authentication**
Users must re-authenticate with third-party services even though they're already logged into your platform.
|
|
**Higher drop-off rates**
Additional authentication steps create friction points that lead to user abandonment and lower conversion rates.
|
|
**Poor user experience**
Users are confused about why they need to create yet another account or log in again during payment flows.
|
|
**Slower transaction flows**
Multiple login steps add unnecessary delays to time-sensitive payment transactions.
|
## Our Solution
Auth Reliance eliminates redundant logins by allowing partners to pass authenticated user credentials directly to Transak, creating a seamless, uninterrupted payment experience.
Here are some of the **key benefits** of the Auth Reliance solution:
|
**Seamless Authentication**
Users stay authenticated without re-entering credentials or creating new accounts.
|
|
**Higher Conversion**
Reduce friction and drop-offs by eliminating redundant authentication steps.
|
|
**Better UX**
Keep users in your app's flow without disrupting their journey.
|
|
**Backend Security**
Server-to-server authentication with IP whitelisting ensures secure transactions.
|
## How does it work?
## Current Limitations
|
Limitation
|
Details
|
|
**Backend-only calls**
|
Auth Reliance APIs are to be called only from the partner backend and subjected to the whitelisting of partner IP addresses. Direct API calls from the frontend apps are not supported.
|
|
**Email verification**
|
Email verification via OTP is partner's responsibility and must be completed before email is submitted to Transak. By passing the email address to Transak via `x-user-identifier`, you confirm that it has already been verified on your side.
|
### Supported Features
|
Supported
|
Feature
|
|
Yes
|
Bank transfers, Open banking, Headless Apple Pay, Headless Google Pay, Headless Cards
|
|
No
|
Semi Widget - Cards, Apple Pay and Google Pay
|
## How to integrate?
### Enable Auth Reliance
#### Contact & Request Auth Reliance access
Follow the steps in the [Need help in Integration](/getting-started/help-and-support#need-help-in-integration) section to reach us. Then raise the request to enable **Auth Reliance** for your API key.
#### Whitelist your IP addresses
Share your public IP addresses with Transak for whitelisting.
### Configuration
#### Call Onboard User API (using Backend Only)
Use [Onboard User API](/api/whitelabel/user/onboard-user-auth-reliance) to create the user or fetch the existing user
details for Auth Reliance.
Sample request:
```bash
curl --location --request POST 'https://api-gateway-stg.transak.com/api/v2/user/onboard' \
--header 'x-user-identifier: USER_IDENTIFIER' \
--header 'x-access-token: PARTNER_ACCESS_TOKEN'
```
This API must be called before any other API that uses Auth Reliance. If user isn't onboarded, subsequent Auth Reliance requests will fail with below `error`:
```json
{
"error": {
"statusCode": 404,
"message": "User not found. Please onboard the user first.",
"errorCode": 1023
}
}
```
#### Include required headers in all other requests
Include these headers in your [Whitelabel API requests](/api/whitelabel).
These are required for Auth Reliance to
identify the authenticated user and authorize the request:
|
**`x-access-token`** `string` — required
Partner access token (see [guide](/guides/how-to-create-partner-access-token))
---
**`x-user-identifier`** `string` — required
User's email address
---
|
> Authenticate users without requiring re-login into Transak's flow