Identify visitors
Identity verification lets Zorvia associate a signed-in user with a stable external ID. Generate the signature on your server, then pass the signed payload to the SDK.
Never expose the identity signing secret in JavaScript, mobile code, logs, or API responses. Only the public messenger key belongs in client code.
Build the signed payload
The payload can contain external_id, name, email, phone, custom_data, and timestamp. It is recursively sorted by key, JSON encoded without escaped slashes or Unicode, and signed using HMAC-SHA256.
Generate a fresh timestamp for each identity response. Zorvia rejects stale signatures.
Identify through the SDK
Call identify() after init() succeeds:
The identity object must include external_id, timestamp, and signature. It may also include name, email, phone, and custom_data.
