Skip to main content
Altcraft Docs LogoAltcraft Docs Logo
User guide iconUser guide
Developer guide iconDeveloper guide
Admin guide iconAdmin guide
English
  • Русский
  • English
Login
    User API documentationAPI interactionMatching
      Profilesarrow
    • Import profileUpdate profileImport multiple profilesUpdate multiple profilesAdd multiple profilesAdd profile to databaseImport profile to RabbitMQGet profile dataUploading profiles to a fileDelete profileSubscription fields functional updateDatabase fields functional updateMerging multiple profilesUnsubscribe profile from resourceProfile splitting
        Subscriptionsarrow
      • Add or edit subscriptionGet all profile subscriptionsGet all subscriptions from multiple profilesGet profile subscriptionDelete profile subscriptionRestore deleted subscriptionSuspend all subscriptionsUnsuspend all suspended subscriptions
        Action historyarrow
      • Get profile action historyGet multiple profiles action history
        Profile relationsarrow
      • Attach relationDetach relationModify relation propertiesOverwrite relation propertiesGet profile relations infoGet profile relations info
      Get data for multiple profiles
      Databasesarrow
    • Get database statisticsUpdate statistics on databaseGet database listGet database informationGet database fieldsDatabase wipe
      Resourcesarrow
    • Get resource statisticsUpdate statistics on resourceGet resources listGet resource informationGet resource subscription fields
      Segmentsarrow
    • Create segmentGet statistics on resourceUpdate statistics on segmentAdd or remove profileGet profile data in a static segmentUpdate segmentGet segment informationGet segments listDelete segment
      Suppression listsarrow
    • Create suppression listUpdate suppression listGet suppression list infoGet the list of suppression listsDelete suppression listUpload suppression list data to file
        Suppression list actionsarrow
      • Check if email is suppressedAdd email to suppression listAdd multiple emails to suppression listRemove email from suppression listRemove all emails from suppression listCheck if domain is suppressedAdd domain to suppression listAdd multiple domains to suppression listRemove domain from suppression listRemove all domains from suppression listCheck if phone number is suppressedAdd phone number to suppression listAdd multiple phones to suppression listRemove phone number from suppression listRemove all phone numbers from suppression list
      Templates and fragmentsarrow
    • Get templates listGet template infoDelete templateAdd templateUpdate templateChannel object
      Campaignsarrow
    • Get campaign informationGet campaign listActivate campaignComplete campaignDeactivate campaignGet campaign status
      Mailingsarrow
    • Activate mailingDeactivate mailingGet mailing listGet mailing informationGet mailing logClone mailingDelete mailingGet mailing status
        Broadcast mailingsarrow
      • Get broadcasts listGet broadcast informationCreate broadcast mailingUpdate broadcast mailingLaunch a broadcast mailing
        Regular mailingsarrow
      • Get regular mailings listGet regular mailing informationCreate regular mailingUpdate regular mailingLaunch a regular mailing
        Trigger mailingsarrow
      • Get trigger mailings listGet trigger mailing informationCreate trigger mailingUpdate trigger mailingTrigger launch (API call)Profile import + trigger mailing launchTask for bulk trigger launchTask for bulk profiles import + trigger launchBulk trigger launchBulk profiles import + trigger mailing launchClone a trigger mailingData array
      Automation scenariosarrow
    • Engage profile in scenarioImport and engage profile in scenarioBatch import and engage profiles in a scenarioTask for batch import and engaging profiles in the scenarioGet scenarios listActivate scenarioDeactivate scenarioGet scenario informationChange scenario priority
      Loyalty Programsarrow
    • Get profile tier in a loyalty programExport points transactionsExpiring points for a periodGet profile account transactionsGet trigger promotions listAccrue points to a memberRedeem member pointsCommit temporary transactionPreliminary Order CalculationOrder ConfirmationRoll back temporary transactionCancel points transactionGet points account balanceRegister member in a loyalty programBatch adding participants to loyalty programTask for batch add participants to loyalty programRemove member from loyalty program
      Formsarrow
    • Get form informationGet form listExport form fill data by userExport form fill dataPublish formUnpublish formDelete form
      Promo codesarrow
    • Import promo codesGet promo code informationActivate promo codeUpdate promo codeAttach promo codeDetach promo codeGet all promo codes
      Goalsarrow
    • Goals and goal values registration
      Application push notificationsarrow
    • Processing and adding a subscriptionAdd app push events
      Marketarrow
      • Market objectsarrow
      • Order data objectProduct data objectSKU data objectCategories arrayCustom fields array
        Ordersarrow
      • Import order and item statusesGet orders listDelete orderGet order statusUpdate order line status
        Products and SKUarrow
      • Import products, SKUs and categoriesImport SKUs and categoriesGet products listGet SKUs listDelete productsDelete SKU
      Analytic reportsarrow
    • Get summary reportGet soft bounces reportGet undeliveries report
      Sendersarrow
    • Get senders list
        Virtual senders (Smart accounts only)arrow
      • Get virtual senders listGet virtual sender informationClone virtual senderCreate virtual senderUpdate virtual senderDelete virtual sender
      External datatables queriesarrow
      • Segmentation queriesarrow
      • Add segmentation queryUpdate segmentation queryGet segmentation query informationGet segmentation queries listDelete segmentation query
        Template queriesarrow
      • Add template queryUpdate template queryGet template query informationGet template queries listDelete template query
      Objectsarrow
    • AKMTA objectContent objectCustom channels rulesEmail rule objectFile objectProfile data objectSMS rule objectSender objectSender typesStart schedule objectSubscription objectTrigger types
      Miscellaneousarrow
    • Upload fileGet message web versionPush providersDeduplication of requestsHow to send API request with RabbitMQList of gender identificationsObtain valid values for fields: browsers, devices, tz, oses, languages
    Importing the API collection in PostmanList of API endpoints
      SDKarrow
      • mSDKarrow
        • Androidarrow
        • Quick startSDK functionalitySDK ConfigurationPublic SDK API
            Provider setuparrow
          • Firebase Cloud MessagingHuawei Mobile ServicesRuStore
          iOSarrow
        • Quick startSDK configurationSDK functionalityPublic SDK API
            Provider configurationarrow
          • Apple Push Notification ServiceFirebase Cloud MessagingHuawei Mobile Services
          React Native (Android/iOS)arrow
        • Quick StartSDK ConfigurationSDK FunctionalityPublic SDK APIProvider setup
          Flutter (Android/iOS)arrow
        • Quick StartSDK ConfigurationSDK FunctionalitySDK Public APIProvider Setup
        Working with role and JWT tokens
      Web Push SDK
  • SDK
  • mSDK
  • Working with role and JWT tokens

Working with role and JWT tokens

Authorization options​

JWT token​

This type of authorization uses a JWT token that the app passes to the SDK. The token is added to the header of every request.

JWT (JSON Web Token) is a string in JSON format containing claims (a set of data) signed for authenticity and integrity verification.

The token is generated and signed with an encryption key on the client's server side (encryption keys are not stored in the app). Upon the SDK's request, the app must provide the JWT token received from the server.

Advantages:

  • Improved security of API requests.
  • Ability to search profiles by any identifiers (email, phone number, custom ID).
  • Support for multiple users on a single device.
  • Restoring access to a profile after the app is reinstalled.
  • Identification of a specific profile across different devices.

rToken​

An alternative authorization method is using a role token (rToken) passed in the SDK configuration parameters. With this authorization method, requests include a header with the role token.

Notes:

  • Profile search is possible only by the device push token (for example, FCM).
  • If the push token changes and is not sent to the server (for example, after the app is deleted and reinstalled), the link to the profile is lost, and a new profile is created as a result.

Limitations:

  • Loss of the link to the profile when the push token changes and this change is not recorded on the Altcraft Platform.
  • No ability to use the app for different profiles on the same device.
  • No ability to register the same user on another device.

Setting up the role token and the JWT provisioning service​

After you create a resource, its settings include a section for managing tokens:

To create a role token, you do not need to add a public key. Simply specify its name, expiration date, and the profile database it is bound to:

The role token serves as an access key from the mSDK side to a specific "resource–database" pair. With authorization using this token, the following actions are available in the platform:

  • Registering events
  • Updating profile fields
  • Importing profiles

To create a JWT token, you need to provide a public key. The platform allows using the ES384 algorithm (ECDSA, as the most reliable), but RS256, ES256, and ES512 can also be used for compatibility with the libraries of different apps.

Generating the key

In this example, let's generate a key using the ES384 algorithm: openssl ecparam -name secp384r1 -genkey -noout -out private.ec.key openssl ec -in private.ec.key -pubout -out public.pem Files with the private key and the public key will be generated. The public key is needed for insertion into the platform.

After the token is created, you can copy it and use it later:

Authorizing mSDK requests with the role token​

When rToken is used for authorization, it provides access to operations within a specific resource. However, due to its open format and immutable value, a restriction is introduced on the profile matching that can be used.

Specifically, when using a role token, profiles are searched by a set of query parameters. In the current implementation, the backend expects the following query parameters when using rToken:

  • provider — mobile notification provider
  • subscription_id — the device token provided by the provider

The profile search is performed by the subscription identifier within the databases assigned to the resource.

Notes​

  • Profile search is possible only by the device push token (for example, FCM).
  • When importing a profile via a push subscription, it is marked as "temporary".
  • When registering app events, linking to a profile (writing to the profile event history) is not possible.
  • If the push token changes and is not sent to the server (for example, after the app is deleted and reinstalled), the link to the profile is lost, and a new profile is created.

Usage​

When using the Altcraft SDK library, the token is specified as the rToken parameter of the AltcraftConfiguration configuration class.

After that, the library provides it as the authorization header.

Authorizing mSDK requests with a JWT token​

For secure authorization in the platform, we recommend using a JWT token to authorize requests. The token must be signed with the paired key that was added earlier, during token creation.

Key features​

  • Increased security of API requests. JWT acts as a protective wrapper around the role token, preventing unauthorized actions. The role token is embedded in the JWT token payload, and only with the keys previously provided (in the resource settings) does the platform authorize mSDK actions.
  • Ability to search profiles by any identifiers (email, phone number, custom ID), in accordance with matching.
  • Support for multiple users on a single device.
  • Identification of a specific profile across different devices.
  • Restoring access to a profile after the app is reinstalled.

Usage​

As the JWT payload, the platform expects the following structure:

{ 
"iss": "<App Name>",
"exp": <UnixTimeUTC>,
"rtoken": "<RoleToken>",
"matching": "JSONString",
}
  • iss — issuer — the unique identifier of the token creator
  • exp — expiration time — the token expiration time as a UNIX timestamp in seconds
  • rtoken — the role token obtained when configuring the resource in the platform
  • matching — JSONString — a string-serialized object, composed in accordance with the documentation. For example: {"db_id":2,"email":"registered_db@localhost","matching":"email_profile"}.

When using the Altcraft SDK library, it is passed as an implementation of the JWTInterface authorization interface. After that, the library likewise provides it as the authorization header.

Example of what the final JWT may look like:

Last updated on Sep 28, 2026
Previous
Provider Setup
Next
Web Push SDK
  • Authorization options
    • JWT token
    • rToken
  • Setting up the role token and the JWT provisioning service
  • Authorizing mSDK requests with the role token
    • Notes
    • Usage
  • Authorizing mSDK requests with a JWT token
    • Key features
    • Usage
© 2015 - 2026 Altcraft, LLC. All rights reserved.