Verify a token in the browser.
This calls the lifecheck-verify Edge Function, which keeps
your secret key on the server and answers with a CORS-enabled verdict. That is what lets a
static page check a token without a backend of its own and without ever shipping the secret.
The full flow is written up in the docs.
1 Pass the check to mint a token
Paste a site key, load the widget, and pass it. A real lc_site_
key from the API keys page mints a server token you can genuinely verify. A preview key mints
a local one, which comes back invalid-input-token - still a
clean test that the endpoint and CORS are alive.
2 Verify the token
Sends { sitekey, token } to the function. Watch for a network or CORS failure against a real JSON verdict.
Not deployed yet? Run supabase functions deploy lifecheck-verify
- the config already sets verify_jwt=false - then reload this page.