{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-mwa/docs/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Partner Token Pass-Through","description":"Gateway to technical documentation for EGYM Platform."},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"partner-token-pass-through","__idx":0},"children":["Partner Token Pass-Through"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"overview","__idx":1},"children":["Overview"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Partner Token Pass-Through enables your Micro Web Application (MWA) to call your own partner APIs directly — without requiring members to log in again inside the MWA."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When a member opens your MWA inside the EGYM BMA app, the EGYM platform securely fetches your partner OAuth access token and injects it into the MWA's ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/mwa/docs/native_interface_and_plugins#initial-context"},"children":["initial context"]}," alongside the standard ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authToken"]},". Your MWA can then use this token to authenticate directly against your backend APIs."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Not all BMA have partner token pass-through option, it's obtained during login process for specific kind of integration."," ","Also, Mobile app should have been released since 20 July 2026 to have a fresh code."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-it-works","__idx":2},"children":["How It Works"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"Member opens your MWA in EGYM BMA\n         │\n         ▼\n  BMA fetches your partner token from EGYM Galaxy backend\n  (token is refreshed automatically if near expiry)\n         │\n         ▼\n  Token is injected into Portals initialContext:\n  {\n    authToken:     \"<EGYM Firebase JWT>\",   ← existing, unchanged\n    partnerTokens: \"{\\\"<alias>\\\":\\\"...\\\"}\"  ← new (JSON-encoded map)\n  }\n         │\n         ▼\n  Your MWA reads the token and calls your partner API:\n  Authorization: Bearer <partnerTokens[\"<alias>\"]>\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This flow is ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["deny-by-default"]},": tokens are only fetched and injected for MWA features that have been explicitly allowlisted by EGYM via configuration. MWAs that are not configured to receive partner tokens are unaffected."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"prerequisites","__idx":3},"children":["Prerequisites"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For your MWA to receive a partner token:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Your partner account must be linked"]}," — the member must have previously linked their partner account through the EGYM authentication flow. If the account is not linked, the token will not be present."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The feature must be allowlisted"]}," — EGYM configures your specific MWA feature with your partner alias. No code changes are needed on EGYM's side to add new partners; it is a configuration-only change."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"reading-the-token-in-your-mwa","__idx":4},"children":["Reading the Token in Your MWA"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["partnerTokens"]}," field in the initial context is a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["JSON-encoded string"]}," containing a map of partner alias → access token."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"typescript","header":{"controls":{"copy":{}}},"source":"import { getInitialContext } from '@ionic/portals';\n\ninterface PortalsContext {\n  authToken?: string;\n  partnerTokens?: string; // JSON-encoded Record<string, string>\n  // ... other fields\n}\n\nconst context = getInitialContext<PortalsContext>()?.value ?? {};\n\n// Parse the partner tokens map (be defensive: JSON.parse can throw)\nlet partnerTokens: Record<string, string> = {};\ntry {\n  partnerTokens = JSON.parse(context.partnerTokens ?? '{}') as Record<string, string>;\n} catch {\n  partnerTokens = {};\n}\n// Read your token using your partner alias (provided by EGYM)\nconst myToken = partnerTokens['<your-partner-alias>'];\n\nif (myToken) {\n  // Use the token to call your API\n  fetch('https://api.yourpartner.com/api/v1/member', {\n    headers: { Authorization: `Bearer ${myToken}` },\n  });\n} else {\n  // Handle gracefully: member account not linked or feature not configured\n}\n","lang":"typescript"},"children":[]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Your partner alias"]}," is assigned by EGYM and matches the identifier used in the EGYM backend to store your OAuth credentials. Contact your EGYM integration team if you are unsure of your alias."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"handling-the-absent-token","__idx":5},"children":["Handling the Absent Token"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Your MWA ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["must"]}," handle the case where ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["partnerTokens"]}," is absent or empty. This happens when:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The member has not linked their partner account."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The feature flag is off or the MWA is not on the allowlist."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A token refresh failure occurred on the backend."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Show a clear error or empty state in these cases — do not assume the token will always be present."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security-guidelines","__idx":6},"children":["Security Guidelines"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Do not persist the token to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["localStorage"]}]}," or any other client-side storage without a security review. Tokens are short-lived and should be used in-memory only."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Tokens are automatically refreshed by the EGYM BMA during silent re-authentication (approximately every 3 hours). A fresh token will be available the next time the MWA is opened."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The token is scoped strictly to your MWA feature — other MWAs cannot access your partner token."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"benefits","__idx":7},"children":["Benefits"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Benefit"},"children":["Benefit"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No re-authentication"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Members are never prompted to log in again inside the MWA."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Seamless experience"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Your MWA loads ready-to-use, with API access available immediately."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Automatic token refresh"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["EGYM refreshes expiring tokens transparently before injecting them."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Config-driven extensibility"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Adding support for additional partners or features requires no code changes on either side."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"token-refresh","__idx":8},"children":["Token Refresh"]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Note:"]}," Support for Partner Token Pass-Through requires a dedicated mobile release on the EGYM BMA side. The timeline for production availability will be shared separately. In the meantime, the team is continuing with improvements and testing."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Tokens injected at MWA launch are valid for a limited time. If your MWA detects that the partner token has expired (e.g. your API returns a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["401"]},"), you can request a fresh token without reloading the MWA."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"how-to-request-a-token-refresh","__idx":9},"children":["How to Request a Token Refresh"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Step 1 — Subscribe"]}," to receive the refreshed token:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"typescript","header":{"controls":{"copy":{}}},"source":"import { portalsSubscribe } from '@ionic/portals';\n\nportalsSubscribe('partnerTokens', (result) => {\n  const partnerTokens = JSON.parse(result.data ?? '{}') as Record<string, string>;\n  const myToken = partnerTokens['<your-partner-alias>'];\n  // use the refreshed token\n});\n","lang":"typescript"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Step 2 — Publish"]}," a refresh request to trigger the native app to fetch a new token:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"typescript","header":{"controls":{"copy":{}}},"source":"import { publish } from '@ionic/portals';\n\npublish({\n  topic: 'subscription',\n  data: {\n    type: 'partnerTokens',\n    data: null,\n  },\n});\n","lang":"typescript"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The native BMA will fetch a fresh token from the EGYM backend and deliver it to MWA via the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["partnerTokens"]}," subscription."]},{"$$mdtype":"Tag","name":"blockquote","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Make sure to set up the subscription ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["before"]}," publishing the request, so you don't miss the response."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"coordination-with-egym","__idx":10},"children":["Coordination with EGYM"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To enable Partner Token Pass-Through for your MWA, work with your EGYM integration team to:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm your ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["partner alias"]}," used in EGYM ."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Have EGYM configure your MWA feature with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["passPartnerTokens = true"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["partnerTokenAliases = [\"<your-alias>\"]"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Verify your OAuth token TTL with EGYM — very long-lived tokens (e.g., 1 day) may be subject to additional review."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For questions, contact EGYM team or refer to the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/mwa/docs/native_interface_and_plugins"},"children":["Integration API documentation"]},"."]}]},"headings":[{"value":"Partner Token Pass-Through","id":"partner-token-pass-through","depth":1},{"value":"Overview","id":"overview","depth":2},{"value":"How It Works","id":"how-it-works","depth":2},{"value":"Prerequisites","id":"prerequisites","depth":2},{"value":"Reading the Token in Your MWA","id":"reading-the-token-in-your-mwa","depth":2},{"value":"Handling the Absent Token","id":"handling-the-absent-token","depth":2},{"value":"Security Guidelines","id":"security-guidelines","depth":2},{"value":"Benefits","id":"benefits","depth":2},{"value":"Token Refresh","id":"token-refresh","depth":2},{"value":"How to Request a Token Refresh","id":"how-to-request-a-token-refresh","depth":3},{"value":"Coordination with EGYM","id":"coordination-with-egym","depth":2}],"frontmatter":{"seo":{"title":"Partner Token Pass-Through"}},"lastModified":"2026-07-13T09:32:18.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/mwa/docs/partner-token-pass-through","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}