Skip to main content

Set up Identity Verification (Deprecated, use secure installation guide instead)

Prevent impersonation and make your Featurebase setup more secure.

Written By Robi Rohumaa

Last updated 4 days ago

Identity verification works for old installations, but for new installations, please refer to: Secure your installation (required by default)


Set up Identity Verification

Start by finding your identity verification secret from Settings → Identity Verification

Generate an HMAC code on your server

First, decide how you'd like to uniquely identify your users — by User ID or Email. You’ll then generate HMAC from the identifier signed with your secret.

import crypto from "crypto";

// Your identity verification secret
const secretKey = "iv_your-secret-key"; 

// Use email or user identifier
const userIdentifier = currentUser.email; 

// Generate HMAC hash
const userHash = crypto
    .createHmac('sha256', secretKey)
    .update(userIdentifier)
    .digest('hex');

NB! Keep your secret secure! Never store it in your repository, client-side code, or anywhere a third party could access it.


Update your code to send the HMAC

Find all places in your codebase where you’ve used the Featurebase("identify", {...}) SDK call and add the user hash there like this:

Featurebase("identify", {
  organization: "yourorg",
  "email": "user@example.com",
  ...otherFields,
  userHash: "user-hash-for-this-specific-user"
})

Optional: Company Identity Verification

You can optionally also enable identity verification for the company attribute to ensure the user is from the company they claim to be from.

Company hashes are created the same way as user hashes. Hash the company ID with your identity verification secret and pass it as a companyHash attribute to the company.

Each company you attach to a user must have a valid hash if this setting is enabled.

Featurebase("identify", {
  organization: "yourorg",
  email: "user@example.com",
  userHash: "user-hash-for-this-specific-user",
  companies: [
    {
      "id": "123",
      "companyHash": "company-hash-created-from-company-id",
      ...otherFields
    }
  ]
  ...otherFields,
})


Testing if a user hash is valid

To test if a user hash is valid:

  1. Go to Settings → Identity Verification

  2. Enter the User ID/Email into the Test Your Identity Verification Hash (HMAC) section

  3. Compare if the hash your server generates matches the one displayed in the Featurebase dashboard.


Enforcing Identity Verification

If you’ve successfully updated your code to include the userHash field and encounter no errors, you can now enforce Identity Verification by toggling the checkbox in Settings → Identity Verification

Once enforced, all requests without a valid user hash will be rejected, ensuring that user impersonation is impossible.


Turning off Identity Verification

You can always disable Identity Verification by unchecking the Enforce Identity Verification checkbox in Settings → Identity Verification

Keep in mind that disabling this will open you up for user impersonation attacks.


FAQ

It’s not possible to rotate the Identity Verification secret yourself. Please contact us via the live chat or email team@featurebase.app to request a rotation.

If you fear your identity verification secret may have been exposed, you can temporarily restrict the visibility of your organization by making it private from Settings → Privacy.

This makes everything visible to admins only and disallows user impersonation attacks.

Still need help? Ask the team