auth() and signOut() calls. Keep the same server-owned customer identity and Push lifecycle.
Files you will add
1. Install the dependencies and worker
2. Configure the environment
Add the following values to.env.local and to your deployment environment:
3. Sign the authenticated customer proof
Createsrc/lib/sagepilot-push-proof.ts:
session.user.id must be your stable customer ID. Do not use a request-body customer ID, a browser-generated UUID or an ID that changes between logins.
4. Expose the proof through the logged-in session
Createsrc/app/api/sagepilot/push-proof/route.ts:
session.user.id. If your auth library uses another field, map it on the server before calling createSagepilotPushProof().
Expose a typed customer ID from Auth.js
Expose a typed customer ID from Auth.js
Add Then preserve your existing authentication configuration and map its stable account ID in the Auth.js session callback. For JWT sessions, If you use an Auth.js database adapter, map your adapter’s stable
src/types/next-auth.d.ts when your application has not already extended the Auth.js session:token.sub is normally the authenticated user’s stable ID:user.id instead. Do not replace it with an email address or a browser-provided value.5. Own the browser lifecycle in one module
Createsrc/lib/sagepilot-push-client.ts:
logout(), allowing the next page load to finish revocation before another customer is identified.
6. Connect after login and show explicit consent
Createsrc/components/sagepilot-push-controls.tsx:
src/app/layout.tsx so every same-origin notification destination initializes the add-on and can flush destination_opened:
connectSagepilotPush() runs after login or a signed-in page reload. It never opens the browser permission prompt. Only the visible button calls subscribe().
7. Revoke Push before Auth.js logout
Createsrc/components/sign-out-button.tsx:
src/app/page.tsx:
8. Verify the full flow
- Open
/sagepilot-push/sagepilot-push-worker.jsand confirm it returns JavaScript with status200. - Sign in and confirm the proof request returns
200; it must return401when signed out. - Confirm the page shows Enable marketing notifications without opening a browser prompt automatically.
- Click the button, allow notifications and confirm the UI changes to Marketing notifications are enabled.
- Send a real Journey or Campaign to a test segment containing this customer.
- Click the notification and confirm the same-origin destination opens.
- Verify
received,openedanddestination_openedseparately in Push analytics. - Sign out, send again and confirm that this browser endpoint is no longer eligible.