Yandex ID One Tap Sign-In
Yandex ID One Tap Sign-In
Yandex ID One Tap Sign-In
The add-on brings Yandex ID sign-in to the storefront: the Yandex button in the sign-in and registration forms and the Instant sign-in widget for guests. A visitor already signed in to Yandex in the browser sees their name and portrait on the button; one click, a short confirmation in the Yandex window, and the customer is in. No password and no confirmation e-mail are needed.
New customers. If there is no account with the e-mail of the Yandex account, one is created automatically: the first name, last name, e-mail and, when the customer permits, the phone number come from Yandex ID. The store's standard registration e-mail can be sent to the customer.
Existing customers. If the e-mail is already registered, the customer enters their own account and Yandex ID gets linked to the profile. The link is visible in the customer area, where it can be removed or set up again. Orders placed as a guest before signing in are attached to the account.
Security. The store verifies the token received in the browser itself with a direct request to Yandex and accepts only a token issued to your application. No application secret is needed. Only customers can sign in through Yandex ID; administrator and vendor accounts are never affected. Sign-in can be limited to certain e-mail domains.
The add-on settings — the Client ID, the look of the button, the widget, the rules for creating and linking accounts, the log of rejected sign-ins — are set on the Add-ons → CS-Commerce Addons → Yandex ID One Tap Sign-In page.
The add-on needs an OAuth application at oauth.yandex.ru (see Setting up the Yandex OAuth application) and a storefront served over HTTPS: Yandex instant sign-in works on secure pages only.
The add-on works with CS-Cart and Multi-Vendor starting from version 4.3.1 and supports the CS-Cart, CS-Cart Ultimate, Multi-Vendor, Multi-Vendor Plus and Multi-Vendor Ultimate editions.
On the storefront the add-on plugs in through the standard hooks of the Responsive theme and themes based on it. The Yandex button is rendered by the index:login_buttons hook of the views/auth/login_form.tpl template, which is used by the sign-in pop-up, the sign-in page, the My account block and the sign-in forms at checkout; the block on the registration page and in the customer profile uses the profiles:account_update hook of views/profiles/update.tpl. If your theme overrides these templates without the hooks, the button and the linking block will not appear until the hooks are put back.
The button and the widget are drawn by the Yandex SDK (passport-sdk) loaded from yastatic.net and working through an iframe. It needs a storefront served over HTTPS and the customer's browser being able to reach Yandex. If the SDK fails to load (for example, it is blocked by a browser extension), the button placeholders are hidden after 15 seconds and the regular sign-in form keeps working. The personalised button with the name and portrait and the Instant sign-in widget rely on third-party cookies: in Safari, Firefox in strict mode or with ad blockers the widget does not appear, while the button still works, just without the name and portrait.
On Multi-Vendor only customers sign in through Yandex ID: vendor and administrator accounts are never affected. In editions with several storefronts the settings are kept per storefront.
Next to the Google One Tap Sign-In add-on by CS-Commerce the Yandex and Google buttons line up in one column under a shared divider.
If the add-on conflicts with your theme or another solution, please contact our support center.
After success payment, your order will be automatically marked as Paid within a few minutes. Once order changed to Paid status - add-on License activation passed success and you will received an e-mail with confirmation the receipt of payment and a second e-mail with a download add-on link. You can also download the add-on in our License Management section of our website. To install the add-on on your website, please follow these steps:
- Download the latest version of the add-on on our website in the "License Management" section or via the link sent by e-mail.
- Go to Add-ons → Manage Add-ons and in the gear button, select Manual Installation.
- Select the downloaded file and complete the installation of the add-on.
Add-on installation is completed. To go to the add-on settings page, select the installed add-on in the top menu Add-ons → CS-Commerce add-on
The add-on settings page is located at Add-ons → CS-Commerce Addons → Yandex ID One Tap Sign-In. You can also get there through Add-ons → Manage add-ons: when you open the add-on settings from the general list, the system redirects you to this page automatically.
All the settings sit on a single General settings tab in five groups: Yandex OAuth, Sign-in button, Instant sign-in widget, Customer accounts and Diagnostics; each is covered in the General settings article. On the right there are blocks with information about the installed add-on version and the upgrade subscription period, a link to the documentation and an add-on rating form.

While the Client ID field is empty, the add-on shows nothing on the storefront: no button, no widget, no linking block in the profile. How to get a Client ID is described in Setting up the Yandex OAuth application.
Settings per storefront
In the CS-Cart Ultimate and Multi-Vendor Ultimate editions with several storefronts the settings are stored separately for each storefront. The storefront is selected with the switch in the page header. Until a storefront is selected, the fields cannot be changed and the standard Ultimate lock icon appears next to each of them — in the unlocked state the value is written to all storefronts at once.
In Multi-Vendor with a single storefront the settings are shared by the whole marketplace; there are no separate values for vendors.
Access rights
The add-on adds its own privilege group — Manage Yandex ID One Tap Sign-In. It contains two privileges: viewing the settings page and changing it. By default they are not granted to any user group, so an administrator with limited rights will not see the settings page until the privileges are granted to their group.
The privileges affect access to the settings page only. Yandex ID sign-in on the storefront does not depend on administrator rights.
Yandex OAuth
The group starts with the How to get a Client ID note with the ready address of the add-on's auxiliary page for the Redirect URI field and the list of permissions to tick in the application; the process itself is described in Setting up the Yandex OAuth application.
Client ID — the identifier of the OAuth application from oauth.yandex.ru. A required field: while it is empty, Yandex ID sign-in is not shown on the storefront.
Allowed e-mail domains — a comma-separated list of domains, e.g. company.ru, partner.org. When filled in, only accounts with an e-mail in these domains can sign in through Yandex ID; the others see the message Accounts of this e-mail domain are not allowed to sign in here. An empty field accepts any Yandex account.
Sign-in button
Show the button in sign-in forms — enabled by default. Adds the Yandex ID button to the sign-in pop-up, the sign-in page, the checkout sign-in form and the registration page. If the visitor is signed in to Yandex in this browser, the button shows their name and portrait. When disabled, only the widget (if enabled) and the linking block in the customer profile remain on the storefront.
Button type — Main (filled, with caption) (default), Outlined, with caption, Icon on red or Icon on grey. Icon buttons are square and fit compact forms.
Button theme — Light (default) or Dark, to match the background of the sign-in form.
Button size — the base height of the Yandex button from XS to XXL; the default is M, about 40 px. The button stretches to the full width of the form.
Corner radius, px — 4 by default; 0 makes square corners.
Logo language — the letter on the logo: Russian (Я) (default) or English (Y).
Instant sign-in widget
Show the instant sign-in widget to guests — disabled by default. A small Yandex panel appears on the page offering to sign in with the account the visitor is already signed in to in the browser. Signed-in customers never see it.
Below the setting there is the Why the widget or the personalised button may not appear note; the same reasons are covered in the Instant sign-in widget article.

Customer accounts
Create an account for new customers — enabled by default. When no account with the Yandex e-mail exists, a customer profile is created automatically with the name from the account. When disabled, such visitors see the message There is no account with this e-mail yet. Please register first.
Send the standard registration e-mail — enabled by default, shown when account creation is enabled. New customers receive the store's regular "profile created" notification.
Sign in to existing accounts by e-mail — enabled by default. If a customer account with the same e-mail already exists, the customer is signed in to it and Yandex ID is linked to the profile. When disabled, such a customer is asked to sign in with the password first and link Yandex ID in the profile settings.
Keep customers signed in — enabled by default. Works like the Remember me checkbox of the regular sign-in form: the customer session is kept in a cookie and survives closing the browser.
After signing in — where the customer goes once signed in through Yandex ID: Stay on the current page (default), Open the account page or Open a custom address. The last option reveals the Address after signing in field: a store dispatch (e.g. orders.search) or a full URL of a store page.
Diagnostics
Log rejected sign-in attempts — disabled by default. The reasons of failed Yandex ID sign-ins (Yandex did not share an e-mail, disallowed domain, disabled account, an attempt to sign in as an administrator and others) are written to Administration → Logs together with the account e-mail. The reason codes are listed in the Security and logging article.

The add-on needs a Yandex OAuth application: by its identifier (Client ID) Yandex issues a token to the customer, and the store checks that the token was issued to your application. The application secret is not used: the token is verified by a direct request from the store to Yandex.
- Sign in to Yandex OAuth and click Create application → For user authorization. Fill in the service name, icon and contact e-mail.
- Platform — Web services. In the Redirect URI field enter the add-on's auxiliary page; its exact address is shown in the note on the add-on settings page and looks like
https://your-store/index.php?dispatch=csc_yandex_oauth.token. The page has no content of its own: it only receives the token from Yandex and passes it to the store window. - Data access: tick Login, first name, last name, gender, User portrait and E-mail address. Phone number is optional: when the permission is granted and the customer confirms it, the phone goes into the profile.
- Copy the Client ID from the application page into the field of the same name in the add-on settings and save the settings.
Without access to the e-mail address no sign-in is possible: the customer sees the message Yandex did not share an e-mail address. Without access to the first and last name the account is created with the Yandex login instead of the name.
The storefront must be served over HTTPS: Yandex instant sign-in opens secure pages only, and the add-on builds the Redirect URI with https.Where the button appears
With Show the button in sign-in forms enabled, the Yandex ID button is rendered below the regular sign-in form behind an or divider: in the sign-in pop-up in the header, on the sign-in page, in the My account block and in the sign-in forms at checkout. On the registration page the button sits below the form with the line or register in one click. The button is drawn by the Yandex SDK: a visitor already signed in to Yandex in the browser sees their name and portrait on it, everyone else is offered to sign in.

A click on the button opens the Yandex window with a short confirmation. Yandex returns a token to the browser through the add-on's auxiliary page, the add-on sends it to the store, and after verification the customer is signed in. Where they land after signing in is set by After signing in: by default they stay on the same page.
Instant sign-in widget
With Show the instant sign-in widget to guests enabled, a guest sees a Yandex panel in the corner of the page: their account if they are signed in to Yandex in the browser, an offer to sign in otherwise. One click and the sign-in is done, without the sign-in form. Customers signed in to the store never see the panel. Unlike Google One Tap, Yandex has no cooldown: a closed widget simply appears again on the next page load.

The browsers where the widget and the personalised button may not appear are covered in the Instant sign-in widget article.
What happens to the account
- Yandex ID is already linked to a customer — the customer is signed in to that account.
- The e-mail is known to the store, but Yandex ID is not linked yet — with Sign in to existing accounts by e-mail enabled, the customer enters the existing account and Yandex ID gets linked to it. Blank first and last name and a blank phone in the profile are filled from Yandex ID; filled fields are left unchanged. When the setting is disabled, the customer sees a message asking to sign in with the password and link Yandex ID in the profile settings.
- The e-mail is unknown to the store — with Create an account for new customers enabled, a customer account is created: the e-mail and login are the Yandex account address, the first and last name come from Yandex ID (they are also written to the recipient name of the address; without the name permission the Yandex login is used instead), the phone is taken when Yandex shares it, the language is the current storefront language, the password is random. The standard registration e-mail can be sent. The customer sees the message Welcome! Your account has been created and you are signed in. When the setting is disabled, a message asks to register first.
Orders placed as a guest in the same session before signing in are attached to the account. Only customers can sign in through Yandex ID: if the e-mail belongs to an administrator or vendor account, the sign-in is rejected with the message Sign-in with Yandex ID is available to customers only. A disabled customer account is not let in either.
A customer created through Yandex ID is not told any password, but the regular e-mail and password sign-in stays available: a password is set through the standard Forgot your password? link.
Linking the account in the profile
The Yandex ID block appears on the profile page in the customer area. If an account is linked, the block shows the portrait and e-mail of the Yandex account and the Unlink button; after unlinking, a sign-in with this account goes through the e-mail match again.

If no account is linked, the block holds the Yandex button with the hint Link your Yandex ID to sign in to the store without a password: the signed-in customer clicks it and confirms the account that will be linked to the profile.

One Yandex ID can be linked to one customer only: an attempt to link an account already tied to another profile is rejected with the message This Yandex ID is already linked to another customer. When a customer account is deleted, the link is removed with it.
The widget and the personalised button with the name and portrait are drawn by the Yandex SDK in the customer's browser; the add-on merely loads the SDK and requests the widget for guests. Unlike Google One Tap, Yandex has no cooldown after the prompt is closed and Chrome does not block it: a closed widget opens again on the next page load. It depends on an iframe and third-party cookies instead, so it is hidden when the browser:
- blocks third-party cookies — Safari and Firefox in strict mode do this by default, as do many ad blockers. The widget is not shown, the button still works but without the visitor's name and portrait;
- forbids iframes or has JavaScript disabled in them;
- has cookies disabled entirely — the Yandex SDK returns an error and nothing is rendered.
Also nothing is offered when the visitor has no Yandex session in this browser, and the widget is never shown to customers already signed in to the store. The page must be served over HTTPS.
If the Yandex SDK fails to load (for example, it is blocked by a browser extension), after 15 seconds the add-on hides the button placeholders and the customer sees the regular sign-in form without empty gaps. SDK errors are printed to the browser console as a line starting with Yandex ID:.
The same note is shown on the add-on settings page under the Instant sign-in widget group.
Token verification
The Yandex SDK obtains an OAuth token in the customer's browser and passes it to the store window through the add-on's auxiliary page (the Redirect URI); there is no code exchange and no application secret. The add-on sends the token to the store server and verifies it itself:
- a direct request to Yandex (
https://login.yandex.ru/info) with the token returns the customer profile; an invalid token is rejected by Yandex; - the audience — the application identifier in the Yandex response matches the Client ID from the settings;
- the profile carries an e-mail address (the default one or the first shared); without it the sign-in is rejected;
- the e-mail domain is in the Allowed e-mail domains list when one is set.
Storefront requests to the add-on are accepted by POST only and are protected by the standard CS-Cart CSRF token check. The return address after signing in is checked against the store domain: a customer cannot be sent to a foreign site through a link parameter. The auxiliary token page is closed to indexing and hands the token only to a window with your storefront address.
Who can sign in
Only customer accounts sign in through Yandex ID. If the e-mail of the Yandex account belongs to an administrator or a vendor, the sign-in is rejected. Disabled accounts are not let in. One Yandex ID is linked to at most one customer account.
What the add-on stores
The links are kept in the csc_yandex_oauth_users table: the Yandex ID identifier and login, e-mail, name and portrait URL, the linking date, the last sign-in date and the number of sign-ins. Yandex tokens are not stored. A customer created through Yandex ID gets a random password stored the standard way. When a customer is deleted, the link record is removed; when the add-on is uninstalled, the table is dropped with all the links.
Log
With Log rejected sign-in attempts enabled, every failed sign-in is written to Administration → Logs as a csc_yandex_oauth: Sign-in rejected line with the reason code and the account e-mail. The codes and the messages the customer sees:
no_email— Yandex did not share an e-mail address, so this account cannot be used to sign in (the application has no e-mail permission or the customer declined it);domain_not_allowed— Accounts of this e-mail domain are not allowed to sign in here;account_not_found— There is no account with this e-mail yet. Please register first (account creation is disabled);account_exists_not_linked— An account with this e-mail already exists. Sign in with your password and link Yandex ID in the profile settings (sign-in to existing accounts is disabled);account_disabled— This account is disabled;not_customer— Sign-in with Yandex ID is available to customers only;yandex_account_taken— This Yandex ID is already linked to another customer;cant_create_profile— Could not create an account. Please register with the form;yandex_unavailable— Yandex is temporarily unavailable. Please try again in a minute (Yandex did not answer the profile request);malformed_token,token_invalid,bad_audience,login_failed— Could not sign in with Yandex ID. Please try again or use your e-mail and password.
For developers
Before an account is created, the add-on calls the csc_yandex_oauth_create_user hook with the Yandex profile data and the customer data array passed to fn_update_user(): profile fields can be completed or changed there. On the storefront a failed sign-in triggers the ce.csyo.login_failed event with the error code, and the Tygh.csyoRenderButtons() function renders the buttons inside dynamically added markup.
In order to have access to add-on upgrades, you must have an active upgrade subscription. If the subscription period has expired, you will only have access to upgrades released before the expiration date of your subscription. You can renew your upgrades subscription in the "License Management" section on our website.
The add-on supports instant upgrades via the CS-Cart Upgrade Center. The built-in CS-Cart Notification Center (bell) will notify you about new versions release of the add-on. Upgrades via Upgrades Center will allow you to switch to a newer version without losing add-on data and settings.
Before start an upgrade process, it is highly recommended to make a full backup of the site (database and files) of your store using the server or hosting methods.
Upgrade through the Upgrade Center
- In the top menu, go to Administration → Upgrade Center;
- In the gear menu, click "Refresh available upgrades"
- Find and add-on on list of available upgrades and click the Download button and than Install button;
- Follow all the instructions that will be shown during the upgrade process;
- It is recommended to clear the CS-Cart templates cache after the upgrades are installed by deleting the var/cache folder on your server or adding the ctpl parameter to the address bar (example: https://domain.com/admin.php?ctpl).
Addon Reinstallation by uninstall old and install new:
Reinstalling an add-on means deleting the add-on's settings and data. Reinstallation will allow you to get a clean installation of the latest addon version. To reinstall the add-on with saving the add-on settings and data, please contact us via our Support Center to provide this service.
To completely reinstall an add-on without saving data, follow these steps:
- Go to Add-ons → Manage add-ons and find the old installed add-on.
- Click the delete button in the gear menu of the add-on.
- Download the latest version of the add-on on our website in the "License Management" section.
- Go to Add-ons → Manage add-ons and in the gear menu select Manual Installation. Select the previously downloaded file and complete the installation of the add-on.
The technical support of the add-on is already included in its price. Before contacting the support center, please make sure you are using the latest released version of the add-on. Old versions of the add-on are not supported by technical support.
To use our technical support, follow these steps:
- On our support center site https://helpdesk.cs-commerce.com/, log in with your account;
- Click on the "Create ticket" button;
- Fill in all the required fields and create ticket (you will receive a confirmation email);
- Expect a response from a specialist (a notification will be sent to your e-mail about the response) in accordance with the regulations of the technical support service.
If you have not received an answer within the time frame specified in the regulations, write us a message to the e-mail [email protected] with the subject of the ticket and we will try to resolve your issue as soon as possible.
Technical support via chat on the site, direct phone calls or e-mail letters is not provided. All help discuss goes through the support center. Carefully study the documentation for the add-on and the terms of technical support before creating a ticket. We recommend that you familiarize with the general restrictions:
- Fragments of code or some files of an add-on may have a private (encoded) part. The coded part does not create problems on add-on customizations;
- The add-on will work only on those domains that are specified in the user's license. If you try to use the solution the domains of which are not included in the license, the add-on will be automatically disabled;
- Installing on local machines is not allowed by the licensing system. For the add-on to work on an additional domain (alias), specify this alias on the license management page. Up to three aliases are allowed per domain for testing and development purposes. You can change the main license domain yourself on the license management page.
To have possibility to add or change license domains and aliases, the upgrade subscription must be active. To change the license domain of an expired upgrades subscription, you must first renew your subscription.
Version 1.0 of September 28, 2026
- The first release of the add-on: one-click sign-in and registration with Yandex ID, the instant sign-in widget, linking Yandex ID in the customer area, button and account creation settings.