Use cases
SuperPDP OAuth2 onboarding (Authorization Code + KYB)
PKCE flow for sub-tenant KYB via SuperPDP popup
To onboard a new sub-tenant (an SSII's end client), Scell.io delegates KYB and identity verification to SuperPDP via OAuth 2.0 Authorization Code (with PKCE). The Scell.io JavaScript widget (`onboarding.js` on cdn.scell.io) opens a popup to SuperPDP where the end client provides legal info (SIRET, KBIS), goes through identity verification, and SuperPDP redirects to the Scell.io callback with a `code`. On the backend, `POST /onboarding/superpdp/callback` exchanges the code for OAuth tokens (access + refresh) stored encrypted at the sub-tenant level. The Scell.io tenant is created automatically with SuperPDP-verified info.
Key facts
- OAuth 2.0 Authorization Code + PKCE
- JS widget on `cdn.scell.io/widget/v1/onboarding.js`
- KYB + identity check delegated to SuperPDP
- Endpoints: `POST /onboarding/superpdp/authorize` + `/callback`
- OAuth tokens stored AES-256-GCM encrypted per sub-tenant
- Refresh token rotation on each use
Code example
// Frontend : intégration du widget dans une page React
import { useEffect } from 'react';
declare global { interface Window { ScellOnboarding?: any } }
export function OnboardingButton({ publishableKey }: { publishableKey: string }) {
useEffect(() => {
const script = document.createElement('script');
script.src = 'https://cdn.scell.io/widget/v1/onboarding.js';
script.async = true;
document.body.appendChild(script);
return () => { script.remove(); };
}, []);
return (
<button onClick={() => window.ScellOnboarding?.open({
publishableKey,
onComplete: (subTenant) => console.log('Sub-tenant onboarded:', subTenant.id),
onError: (err) => console.error(err),
})}>Démarrer l'onboarding</button>
);
}