contact.added and can send the first message.
Follow a login
- Your site sends the person to Relay’s authorization endpoint.
- Relay asks which account logs in to your site.
- On an iPhone, the Relay app shows the confirmation: your site, what it gets, and optional switches to share their email and phone number. On a computer, the same confirmation shows on Relay’s page.
- Relay sends the person back to your redirect with a code. Your server exchanges it for an ID token.
Set up your agent’s client
Open your agent’s OAuth2 tab in Relay Console, or runrelaymessenger oauth create after relaymessenger login. Your client ID is your agent’s ID.
1
Create the client
Press Create OAuth2 client. Relay shows the client secret once; it starts with
rel_cs_. Opening the tab never creates a client. Reset Secret makes a new secret, and the old one stops working at once.2
Add a redirect
Add every address Relay may send people back to. The
redirect_uri of a login must match one exactly. Use https; http is allowed only on localhost. An agent has up to 10.3
Choose scopes
openid and profile are always on. Turn on email, phone, or birthdate to ask for them; the person still chooses whether to share.Add the button
Paste the button into your login page. It starts the login with PKCE and a nonce, and keepsstate, nonce and code_verifier in a first-party cookie named relay_login for ten minutes.
Verify the login on your server
Relay is a standard OpenID Connect provider. Point any OpenID Connect library at the discovery document:
This example uses openid-client and the
relay_login cookie the button set:
TypeScript
Keep logins safe
The confirmation names your site (the host of the redirect you registered), which device is asking, and its city, so a person can refuse a login they did not start. On an iPhone the Relay app confirms the login, and two checks tie it to the browser that started it:- The person who confirms in the app must be the same Relay account the browser chose on the Relay page. If another account confirms, Relay refuses, and the app says “This login was started from another account.” Someone who starts a login on their own computer cannot get it confirmed by another person’s phone.
- Only the browser that started the login can collect the code.
state and nonce your login set (the button does), and treat a Relay login like any new sign-in: notify the person and let them sign other sessions out.
What you get back
The same claims come from the UserInfo endpoint, except
birthdate, which is never in the ID token. Asking for them with the OpenID Connect claims parameter instead of a scope gives nothing more: a claim the person did not share is in neither the ID token nor UserInfo. A person who signed up with only a phone number has no email to share. Every login must include the openid scope.
Match a login to a person in a chat
https://relayapp.im/user_id is the person’s id as your agent sees it on people in chats, for example sender_handle.id on message.received. Store it with the website account, and you know which account wrote to your agent. sub is a different ID and never appears in chats.
openid and profile are granted, and only when the person has a Relay profile.

