Skip to main content
If you use Bring Your Own Auth (BYOA), you can issue elevated access tokens directly from your backend without prompting the user for re-authentication or MFA. Your backend signs an assertion JWT and the SDK exchanges it for an elevated access token. This is useful when your backend has already verified the user’s identity through its own means (e.g., a session, an internal auth check, or a custom challenge) and you want to authorize a sensitive Dynamic operation without additional user friction. For concepts, scopes, and token lifecycle, see Step-up authentication overview.

Prerequisites

  • @dynamic-labs-sdk/client initialized
  • External auth (BYOA) configured with a JWKS URL in your dashboard
  • The user is already signed in via external auth

How it works

  1. Your backend creates an assertion JWT signed with the same key registered in your environment’s JWKS URL.
  2. The SDK sends this JWT to Dynamic’s backend, which validates the signature and issues an elevated access token.
  3. The elevated token is automatically stored in SDK state and attached to subsequent API calls — no manual token handling is needed.

Assertion JWT requirements

Your backend must sign a JWT with the following claims: Example payload:
The JWT must be signed using the same algorithm and key that corresponds to your environment’s JWKS URL.

Usage

Combining with checkStepUpAuth

You can use checkStepUpAuth to determine whether step-up is required before calling your backend:

When to use external auth vs. other methods

Both approaches produce the same elevated access token and are stored and consumed identically by the SDK.

React

Use useRequestExternalAuthElevatedToken for the token exchange and call the one-shot checkStepUpAuth check directly inside the button handler:
Last modified on June 24, 2026