<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Adding a &#x27;sign up or login CTA&#x27; to your pages for unauthenticated users]]></title><description><![CDATA[<p dir="auto">How can I add a CTA to get users to log in to my news site, like this one from vox?</p>
<p dir="auto"><img src="/community/forum/assets/uploads/files/1791031074135-screenshot-2026-10-03-at-6.37.05-am-resized.png" alt="Screenshot 2026-10-03 at 6.37.05 AM.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://fusionauth.io/community/forum/topic/3209/adding-a-sign-up-or-login-cta-to-your-pages-for-unauthenticated-users</link><generator>RSS for Node</generator><lastBuildDate>Sat, 03 Oct 2026 22:02:22 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3209.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 03 Oct 2026 12:37:57 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Adding a &#x27;sign up or login CTA&#x27; to your pages for unauthenticated users on Sat, 03 Oct 2026 12:50:02 GMT]]></title><description><![CDATA[<p dir="auto">This is going to vary based on your publishing system, but you can use FusionAuth's OIDC <code>prompt=none</code> to see if users have an active SSO session.</p>
<p dir="auto">If the user has checked <code>remember me</code> and has logged in within the <a href="https://fusionauth.io/docs/get-started/core-concepts/types/tenants#oauth" rel="nofollow ugc">tenant session timeout</a>, the request will succeed, otherwise it will fail.</p>
<h4>Step 1: Main Page</h4>
<p dir="auto">This creates the iframe and listens for the result.</p>
<p dir="auto">On your main page, create the hidden iframe targeting FusionAuth with <code>prompt=none</code>. You also listen for a message event from the iframe to know whether to display or hide the CTA &lt;div&gt;, which needs the id <code>trial-cta</code>:</p>
<pre><code>// 1. Listen for the result sent back from the iframe callback page
window.addEventListener('message', (event) =&gt; {
  // Verify the origin matches your application domain for security
  if (event.origin !== window.location.origin) {
    return;
  }

  const ctaDiv = document.getElementById('trial-cta');

  if (event.data &amp;&amp; event.data.type === 'SILENT_AUTH_RESPONSE') {
    if (event.data.status === 'authenticated') {
      // User has an active SSO session; keep CTA hidden
      if (ctaDiv) {
        ctaDiv.style.display = 'none';
      }
    } else if (event.data.status === 'login_required') {
      // User is not authenticated; show the trial CTA popup/div
      if (ctaDiv) {
        ctaDiv.style.display = 'block';
      }
    }
  }
});

// 2. Create the hidden iframe to initiate the prompt=none request
const iframe = document.createElement('iframe');
iframe.style.display = 'none';
iframe.src = 'https://&lt;your-fusionauth-instance&gt;/oauth2/authorize?' +
  'client_id=&lt;YOUR_CLIENT_ID&gt;&amp;' +
  'response_type=code&amp;' +
  'redirect_uri=https://&lt;your-app-domain&gt;/silent-callback.html&amp;' +
  'scope=openid&amp;' +
  'prompt=none&amp;' +
  'state=&lt;YOUR_STATE&gt;';

document.body.appendChild(iframe);
</code></pre>
<h4>Step 2: Callback Page</h4>
<p dir="auto">Configure this page as an authorized redirect URI in your FusionAuth application [Request Parameters].</p>
<p dir="auto">When FusionAuth redirects back with the authorization code code or <code>error=login_required</code>, this page parses the URL and communicates back to the parent window:</p>
<pre><code>// Parse query parameters from the redirect URI
const params = new URLSearchParams(window.location.search);
const code = params.get('code');
const error = params.get('error');

if (code) {
  // Session exists: notify the parent window
  window.parent.postMessage({
    type: 'SILENT_AUTH_RESPONSE',
    status: 'authenticated',
    code: code
  }, window.location.origin);
} else if (error === 'login_required') {
  // No active session: notify the parent window to show CTA
  window.parent.postMessage({
    type: 'SILENT_AUTH_RESPONSE',
    status: 'login_required'
  }, window.location.origin);
}
</code></pre>
<h4>Cautions And Additional Considerations</h4>
<p dir="auto">This won't work across all browsers, especially those with privacy features or if your FusionAuth instance isn't on the same root domain as the application. <a href="https://fusionauth.io/blog/browser-based-oauth-client-security-architecture#vulnerability-6-silent-authentication-abuse" rel="nofollow ugc">More details here</a>.</p>
<p dir="auto">Test the scenarios you need to support.</p>
<p dir="auto">The CTA should include information about how to sign up or log in if the user already has an account.</p>
<p dir="auto">You may want to add server or client side logic to obfuscate the page contents.</p>
]]></description><link>https://fusionauth.io/community/forum/post/8755</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8755</guid><dc:creator><![CDATA[dan]]></dc:creator><pubDate>Sat, 03 Oct 2026 12:50:02 GMT</pubDate></item></channel></rss>