Webphone SDK
Backend token endpoint
Create tokens for the SIP identity authorized by your application’s signed-in user.
Application integration example: provide your own verified authentication middleware, request parsing, CSRF protection where applicable, and server-side user-to-SIP mapping. The route below must match the tokenProvider URL in your frontend.
app.post('/my-backend/illyvoip/browser-token', yourVerifiedAuthMiddleware, async (req, res) => {
const browserClaimsSipIdentity = Object.keys(req.body || {})
.some((key) => /^sip[_-]?user[_-]?id$/i.test(key));
if (browserClaimsSipIdentity) {
return res.status(400).json({
status: 'error',
message: 'SIP identity must come from the authenticated server principal.'
});
}
const sipUserId = String(req.user?.illyvoipSipUserId || '').trim();
if (!/^[A-Za-z0-9_.-]{1,191}$/.test(sipUserId)) {
return res.status(401).json({ status: 'error' });
}
const response = await fetch('https://api.illyvoip.com/api/v1/sip/browser-token', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'X-Api-Key': process.env.ILLYVOIP_API_KEY
},
body: JSON.stringify({
sip_user_id: sipUserId,
region: req.body.region || 'de'
})
});
if (!response.ok) {
return res.status(502).json({ status: 'error', message: 'Unable to create browser token.' });
}
const tokenPayload = await response.json();
res.json(tokenPayload);
});