Skip to main content
The hosted connect page works in any browser, but on a phone it shows a remote browser: the device’s keyboard and password manager cannot reach it and the rendering is not native. Native apps use the Verso SDK instead. The provider’s login opens in the app’s own WebView, with the system browser’s behaviour (native keyboard, autofill, Google sign-in), and the captured session goes to Verso. Everything else is unchanged: the same signed link, the same webhooks, the same API. iOS is available today. Android, React Native and Flutter are next.

iOS

Requirements: iOS 15+, Swift 5.9+, Xcode 15+. Source and issues: github.com/vrsoai/verso-connect-ios.

Install

Swift Package Manager. In Xcode: File › Add Package Dependencies, enter https://github.com/vrsoai/verso-connect-ios, dependency rule “Up to Next Major Version” from 0.1.0. Or in Package.swift:

Use

Your backend signs a connect link with signLink() exactly as for the web (purpose: "connect") and returns its url to the app. The app secret never ships in the app. Collect the user’s consent in your own UI before this point, as with the hosted page.
A completion-handler form, VersoConnect.present(link:from:completion:), exists for code that is not async. present opens a sheet with the provider’s login, waits for the user to log in, captures the session and dismisses the sheet itself in every case. It returns the connectionId; your backend receives connection.created with the user’s userRef at the same time, exactly as with the hosted page, and the first sync starts within a minute. The link is single use and valid 15 minutes: fetch a fresh one each time the user taps your button. The login itself must complete within one hour.

Errors

What the SDK does

  1. Sends the link’s token to POST /api/connect-native with action: "start". Verso verifies and consumes the link, creates the user record if needed, sends connect.started, and answers with the provider’s login URL, the name of the session cookie to watch, and a one-time capture credential.
  2. Opens the provider’s login in a WKWebView with a non-persistent data store and the Mobile Safari user agent, so the provider treats it as a browser. Nothing remains on the device afterwards.
  3. Watches the WebView’s cookies. Once the session cookie is present and the session is usable, sends it to Verso with action: "capture". Verso encrypts the credential with a key that exists only for this connection, creates the connection, folds a previous connection of the same account into it (Reconnecting), refuses an account already connected by another user of your app, sends connection.created and starts the first sync.
The SDK never sees your app secret or API key, and the session credential is sent once, over TLS, to Verso only. The endpoint is documented in the API reference for teams building on a platform without an SDK yet.

Android, React Native, Flutter

In progress. Until then, open the hosted connect link in Chrome Custom Tabs or the default browser; see On mobile in the connect flow guide.