# User Tokens
source: https://developer.mastercard.com/mastercard-benefits-and-experiences-portal/documentation/use-cases/use-cases-3/index.md

## User Tokens {#user-tokens}

Single Sign-On (SSO) lets eligible cardholders move from a partner app, website, or digital banking environment to a Mastercard-hosted Priceless page without creating or using a separate Priceless login. The partner authenticates the cardholder and sends the required information to the Priceless Platform. The platform then applies the cardholder's access rules and opens a personalized experience.

For integration flow examples, see [Hybrid API Integration: Simplified Flow](https://developer.mastercard.com/mastercard-benefits-and-experiences-portal/documentation/use-cases/use-cases-8/index.md) and [Hybrid API Integration: Advanced](https://developer.mastercard.com/mastercard-benefits-and-experiences-portal/documentation/use-cases/use-cases-9/index.md).

### When to use SSO {#when-to-use-sso}

SSO is required for these integration models and programs:

* Card Benefits.
* Advanced Hybrid API Integrations.
* Loyalty or card-based programs that require SSO. Your API Integration Manager confirms whether your program requires SSO.

#### Additional capabilities {#additional-capabilities}

SSO can also provide these capabilities when they are configured for your integration:

* Display a co-branded Priceless experience.
* Display experiences available to the cardholder's eligible segment.
* Prefill supported checkout fields with cardholder information when the cardholder has provided consent.

### Prerequisites {#prerequisites}

* Your organization is PCI compliant.
* API credentials are active.
* Your integration is registered for SSO when your selected integration model or program requires it.
* Your app or website can open a Mastercard-hosted page and handle return navigation.

### Create a user token {#create-a-user-token}

Call `POST /user-tokens` after the cardholder signs in to your digital environment. Send only the data required by the API and permitted by the cardholder. The API returns a single-use, short-lived `accessToken` and its expiration time.

Use the token only in the Mastercard-hosted URL returned or provided for your integration. Do not log, modify, decode, or reuse the token.

API Reference: `GET /user-tokens`

### Open the Mastercard-hosted page {#open-the-mastercard-hosted-page}

Add the returned `accessToken` to the hosted-page URL that Mastercard provides for your integration. Open the URL in a browser or WebView, as appropriate for your app or website. For checkout flows, use the token before it expires.

The following diagram shows the SSO authentication and access handoff.
Diagram use-case-3

### PAN encryption {#pan-encryption}

If your integration requires PAN encryption, contact your API Integration Manager for the applicable implementation guidance and certificates. Do not include card data in requests until you complete the required PCI and encryption setup.
Note: SSO is also available for Sweepstakes and Pay\&Get products. Contact your API Integration Manager to confirm support for your program.
