Put Dium inside your product. Keep your members on your site.
Call the partner API from your backend, mount Dium under your own domain, and sign members in with a one-time token.
No SDK to install. Every call is a JSON POST you can make with curl.
What you can build on Dium today
Five real building blocks. We only list what runs in production now.
Partner API
Create Flows, seed sessions and add sponsor pages from your own backend. Plain JSON over HTTPS, one key per partner, scoped by action.
API referenceMount Dium in your own site
A small PHP file on your server puts the full Dium app under a path you choose, such as /community/. Members never leave your domain.
Mount guideSigned autologin
Your server asks Dium for a one-time token that lasts five minutes. The browser swaps it for a session. No second password.
SSO guideIdentity through Moat
Every member has one Moat public key. Names and avatars come from Moat and stay in sync across sites.
How identity worksReal-time rooms
The mounted app gets live replies, DMs and session updates through Echo rooms, with polling as a backup.
What exists todayOne surface can sit in an iframe: the member map
The rest of the app refuses to be framed on purpose. The member map is the exception, and only for origins we have allowed.
Read about embedsFrom zero to a signed-in member in three calls
Get a partner key
We issue keys by hand for now. You tell us your site, your mount path and the actions you need. We add them to our partner registry.
Make your first call
From your server, POST to
/api/auth.phpwithaction: "issue_token"and a member's email. You get a one-time token back.Send the member in
Redirect the browser to
/home/autologin.php?token=.... Dium checks the token, sets the session and opens the Flow.
How to get an API key
There is no self-serve key page yet. The Dium team issues each partner key by hand and sets its scopes with you.
Write to us with the details on the right. We reply with your key, the mount template and a config sample. Ask us to send the key through a password manager or secret-sharing link, not plain email.
What to send us
- Your company and a technical contact
- The origin your server calls from, for example https://acme.com
- The path where Dium should live, for example /learning/dium/
- The actions you need, such as
auth.issue_tokenorexhibit.create - The Flow or event IDs you will manage (your
external_idvalues)
What we set up on our side
- Your key and its scopes in our partner registry
- Your origin on our CORS allowlist
- Your host on our redirect allowlist
- The mount template and config sample for your server
What is not here yet
Straight answers, so you can plan around the gaps.
| You might expect | Status today | What to do instead |
|---|---|---|
| Self-serve API key page | Not built | Keys are issued by the Dium team on request. |
| SDKs (Node, Python, Go, Ruby) | None | Use plain HTTPS. The quickstart has copy-paste snippets for curl, Node, Python and PHP. |
| Outbound webhooks | Proposal only | Read the webhooks page for what exists today and the draft design. |
| Sandbox or test mode | None | Ask for a second key and a test Flow you can delete. |
| OpenAPI file and try-it console | None | The API reference is hand-written from the source. |
| Drop-in JavaScript widget | None | Mount the full app on your path. See widgets and embeds. |
Developer docs
Quickstart
Your first successful call in a few minutes, with curl, Node, Python and PHP.
API reference
Auth headers, scopes, errors, rate limits and every partner action with its fields.
SSO and sign-in
The one-time token flow, cookie rules, redirect allowlists and server code in PHP and Node.
Widgets and embeds
Mount Dium on WordPress, React or any server, and what to do on hosted builders.
Webhooks
Real-time options that exist today, and a draft webhook design we want feedback on.
Brand and design
Logo, colours, type and voice rules for partners who show Dium on their site.
Tell us what you want to build.
Keys are issued by hand today, so every partner talks to a person who knows the code.