PHP code example of trustport / sdk

1. Go to this page and download the library: Download trustport/sdk library. Choose the download type require.

2. Extract the ZIP file and open the index.php.

3. Add this code to the index.php.
    
        
<?php
require_once('vendor/autoload.php');

/* Start to develop here. Best regards https://php-download.com/ */

    

trustport / sdk example snippets



Trustport\Client;
use Trustport\TrustportException;

$tp = new Client(['apiKey' => getenv('TRUSTPORT_API_KEY')]);

// In your login handler, after the password check passes:
$session = $tp->startSession(['subject' => $user->username]);

// Send $session->sid to your frontend, KEEP $session->claimToken on the server.
$_SESSION['tp_sid']   = $session->sid;
$_SESSION['tp_claim'] = $session->claimToken;
echo json_encode(['trustport_sid' => $session->sid]);

// Later (after the widget reports onApproved):
$result = $tp->verifySession([
    'sid'        => $_SESSION['tp_sid'],
    'claimToken' => $_SESSION['tp_claim'],
]);

if ($result->ok) {
    // $result->subject is the verified user. Now upgrade your PHP session.
    $_SESSION['user_id'] = $userId;
}


// /api/login.php
session_start();
stportException;

header('Content-Type: application/json');

$in = json_decode(file_get_contents('php://input'), true) ?: [];
$user = $db->users->findByUsername($in['username'] ?? '');

if (!$user || !password_verify($in['password'] ?? '', $user['password_hash'])) {
    http_response_code(401);
    echo json_encode(['ok' => false]);
    exit;
}

$tp = new Client(['apiKey' => getenv('TRUSTPORT_API_KEY')]);
try {
    $session = $tp->startSession(['subject' => $user['username']]);
} catch (TrustportException $e) {
    http_response_code($e->errorCode === 'subject_not_enrolled' ? 403 : 500);
    echo json_encode(['ok' => false, 'error' => $e->errorCode]);
    exit;
}

$_SESSION['tp_pending'] = [
    'user_id'     => $user['id'],
    'subject'     => $user['username'],
    'sid'         => $session->sid,
    'claim_token' => $session->claimToken,
];
echo json_encode(['ok' => true, 'trustport_sid' => $session->sid]);


// /api/finalise.php
session_start();
e: application/json');

if (empty($_SESSION['tp_pending'])) {
    http_response_code(401);
    echo json_encode(['ok' => false]);
    exit;
}
$p = $_SESSION['tp_pending'];

$tp = new Client(['apiKey' => getenv('TRUSTPORT_API_KEY')]);
$result = $tp->verifySession([
    'sid'        => $p['sid'],
    'claimToken' => $p['claim_token'],
]);

if (!$result->ok || $result->subject !== $p['subject']) {
    http_response_code(401);
    echo json_encode(['ok' => false, 'status' => $result->status]);
    exit;
}

$_SESSION['user_id'] = $p['user_id'];
unset($_SESSION['tp_pending']);
echo json_encode(['ok' => true]);

$session->sid           // string — give to the frontend / widget
$session->claimToken    // string — SERVER ONLY
$session->verifyUrl     // string
$session->qrUrl         // string
$session->expiresAt     // DateTimeImmutable

if ($result->ok) {
    $result->subject;        // string
    $result->userId;         // string
    $result->verifiedAt;     // DateTimeImmutable
} else {
    $result->status;         // "pending" | "expired" | "rejected" | "claimed"
}

catch (TrustportException $e) {
    $e->httpStatus;   // int — HTTP status (0 = transport error)
    $e->errorCode;    // string — e.g. "subject_not_enrolled"
    $e->body;         // array|null — raw response body
    $e->getMessage(); // string
}