Skip to content

Mobile apps

myFlowpay is brought into a native mobile host app with an in-app browser: a browser tab presented full screen over the host app, opened with a launch URL, see Embedded (Mobile). The user opens myFlowpay in the host app, completes the journey in the tab and closing it returns them to the host app.

Use Chrome Custom Tabs on Android and SFSafariViewController on iOS.

What you implement

  1. Request a launch URL from the host app backend at the moment the user opens myFlowpay, not in advance. See Embedded (Mobile).
  2. Open it in the in-app browser. Follow the Partner app guidance below.
val intent = CustomTabsIntent.Builder()
    .setShowTitle(true)
    .build()
intent.launchUrl(context, Uri.parse(launchUrl))
let safari = SFSafariViewController(url: URL(string: launchUrl)!)
safari.dismissButtonStyle = .close
present(safari, animated: true)

Partner app guidance

Until it is used or expires, the launch URL signs in whoever opens it. Treat it as a credential.

  • Request it only when the user acts in the host app, and open it straight away on that user's device.
  • Never send it by email, SMS, push notification or chat. A forwarded URL signs the recipient in to the sender's merchant or customer, where the recipient may then verify their identity or connect their bank account.
  • Do not log it, in the app or in the host app backend, and do not pass it to analytics, error tracking or link shorteners.
  • Do not prefetch it, for example with CustomTabsSession.mayLaunchUrl on Android.

Platform notes

Presentation Platform Notes
Chrome Custom Tabs Android Recommended. Shares the user's Chrome session and cookies.
SFSafariViewController iOS Recommended. Presents full screen with no system consent dialog. The user closes it to return to the host app.

Reopening and resuming

Repeat the same two steps whenever the user needs to get back into the journey. The host app backend can request a fresh launch URL for the same merchant or customer at any time, and the user is returned to where they left off, not to a new application. See Resuming the journey.

An expired session takes the same path: myFlowpay tells the user to return to the host app, where the existing entry point requests the next launch URL.

Limitations

The browser tab is a separate process, so there is no channel between it and the host app:

  • No host app driven logout. Closing the tab does not end the myFlowpay session. The user signs out inside myFlowpay.
  • No host app driven session refresh.
  • No in-app signal of what the user is doing in the tab while it is open.

Progress reaches the host app server-to-server through webhooks.