Skip to main content

Use cases

SuperPDP OAuth2 onboarding (Authorization Code + KYB)

PKCE flow for sub-tenant KYB via SuperPDP popup

To onboard a new sub-tenant (an SSII's end client), Scell.io delegates KYB and identity verification to SuperPDP via OAuth 2.0 Authorization Code (with PKCE). The Scell.io JavaScript widget (`onboarding.js` on cdn.scell.io) opens a popup to SuperPDP where the end client provides legal info (SIRET, KBIS), goes through identity verification, and SuperPDP redirects to the Scell.io callback with a `code`. On the backend, `POST /onboarding/superpdp/callback` exchanges the code for OAuth tokens (access + refresh) stored encrypted at the sub-tenant level. The Scell.io tenant is created automatically with SuperPDP-verified info.

Key facts

  • OAuth 2.0 Authorization Code + PKCE
  • JS widget on `cdn.scell.io/widget/v1/onboarding.js`
  • KYB + identity check delegated to SuperPDP
  • Endpoints: `POST /onboarding/superpdp/authorize` + `/callback`
  • OAuth tokens stored AES-256-GCM encrypted per sub-tenant
  • Refresh token rotation on each use

Code example

// Frontend : intégration du widget dans une page React
import { useEffect } from 'react';

declare global { interface Window { ScellOnboarding?: any } }

export function OnboardingButton({ publishableKey }: { publishableKey: string }) {
  useEffect(() => {
    const script = document.createElement('script');
    script.src = 'https://cdn.scell.io/widget/v1/onboarding.js';
    script.async = true;
    document.body.appendChild(script);
    return () => { script.remove(); };
  }, []);

  return (
    <button onClick={() => window.ScellOnboarding?.open({
      publishableKey,
      onComplete: (subTenant) => console.log('Sub-tenant onboarded:', subTenant.id),
      onError: (err) => console.error(err),
    })}>Démarrer l'onboarding</button>
  );
}

See also

Your cookie preferences

We use cookies to improve your experience. Essential cookies are always active. Cookie policy.