Skip to main content
Create users via: Dashboard (testing) | REST API (production) Test UIDs: cometchat-uid-1 through cometchat-uid-5
After initializing the SDK, the next step is to authenticate your user. CometChat provides two login methods — Auth Key for quick development, and Auth Token for production — both accessed through the login() method.

How It Works

Before You Log In

Create a User

A user must exist in CometChat before they can log in.
  • During development: Create users from the CometChat Dashboard. Five test users are already available with UIDs cometchat-uid-1 through cometchat-uid-5.
  • In production: Call the Create User REST API when a user signs up in your app.
You can also create users from the client side using createUser() (development only):
createUser() with Auth Key is for development only. In production, create users server-side via the REST API. See User Management for full details.

Check for an Existing Session

The SDK persists the logged-in user’s session locally. Before calling login(), always check whether a session already exists — this avoids unnecessary login calls and keeps your app responsive.
If getLoggedinUser() returns null, no active session exists and you need to call login().

Login with Auth Key

Auth Key login is the simplest way to get started. Pass a UID and your Auth Key directly from the client.
Auth Keys are meant for development and testing only. For production, use Auth Token login instead. Never ship Auth Keys in client-side code.
On success, the Promise resolves with a User object containing the logged-in user’s details.

Login with Auth Token

Auth Token login keeps your Auth Key off the client entirely. Your server generates a token via the REST API and passes it to the client.
  1. Create the user via the REST API when they sign up (first time only).
  2. Generate an Auth Token on your server and return it to the client.
  3. Pass the token to login().
On success, the Promise resolves with a User object containing the logged-in user’s details.

Logout

Call logout() when your user logs out of your app. This clears the local session.

Login Listener

You can listen for login and logout events in real time using LoginListener. This is useful for updating UI state or triggering side effects when the auth state changes.

Add a Listener

Remove a Listener

Always remove login listeners when they’re no longer needed (e.g., on component unmount or page navigation). Failing to remove listeners can cause memory leaks and duplicate event handling.

Next Steps

Send Messages

Send your first text, media, or custom message

User Management

Create, update, and delete users programmatically

Connection Status

Monitor the SDK connection state in real time

All Real-Time Listeners

Complete reference for all SDK event listeners