How do I embed login credentials in a URL?

Updated Aug 06, 2019

Why Would You Want to Do This?

This article will show you how to embed login credentials into a url. Why would you want to do this?  Here is an example scenario:

Say that you have a user area on your own website, not on ScreenSteps. You create a site on ScreenSteps that you want those users to have access to but you don't want to go through the hassle of setting up user accounts for everyone on ScreenSteps. You can use this method to provide a link in the user area that will take them to your site on ScreenSteps and automatically log them in under a shared user account.

What to Do

1. First you will want to create a new API Access account. This account will be the login for everyone from your own site.  In this example we will say that the username is "myusers" and the password is "mypassword".

2. Then add this user to a protected site on your account. They will now have permission to view the site.

3. Copy the url for the site and add on the authentication parameters.

IMPORTANT: Don't copy the url the admin area of your account. API Access users cannot access the admin area. Make sure you copy the public url.

If the url for your space was then you would want to add ?login=myusers&password=mypassword to the end. The result would look like this:

4. Put this link on your own website.  

When a user clicks on this url they will be taken to space 2345 and automatically logged in.  Anybody just going to will be asked for a username and password.


Security Considerations

A few things that you should be aware of:

  1. Anybody who has this url can login to the site.  You may want to update the password periodically.
  2. If you use http instead of https for the url then the url will be sent unencrypted. If someone is sniffing your traffic they would be able to see the username and password in the url.


If you need lock-tight security for your content, then you should create reader accounts for each person that is going to access that content or use Single Sign-on

 But if you just need something simple that will keep unauthorized people out of the site while at the same time make it easy for your authorized users to get access to the content then this can be a good solution.

Still Need Help?

Contact Us