Custom authentication for embedded apps
Business and Enterprise organizations can now use the Retool API to authenticate apps that are embedded in an app or website external to Retool.
Once configured, the custom authentication flow exchanges an API token for an embed URL. When a parent app authenticates a user using your preferred authentication method, the parent app makes an API request to Retool to generate an embed URL. This embed URL is a secure, single-use link on the domain of your published app. Loading it in the iframe exchanges the link for a session, sets the cookies the app needs, and then displays the app.
Standard authentication through Retool remains supported.
This flow is available for apps published on a cloud instance that use the standard Retool domain (example.retool.com). It is not available to self-hosted instances or organizations that use a custom domain.