Werify SSO: one sign-in for members and partners
Every Dium sign-in runs through Werify. Partners with Werify on their own site can send members into Dium already signed in.
What it does
Members sign in with an emailed code or a social account through the Werify widget. There is no Dium password to forget.
For partners, Werify SSO lets a member who is signed in on your site open Dium and land signed in. Dium checks the session with Werify on its own server before it trusts it, and only redirects back to hosts on its allowlist.
Werify is also the payment provider behind Pro plans (Werify Paywall), but that is separate from sign-in.
What data moves
| Data | Direction | When |
|---|---|---|
| Email address | Werify to Dium | At sign-in |
| Werify user key | Werify to Dium | At sign-in |
| Moat public key | Werify to Dium | At sign-in, links the member to their profile |
| Sign-in method (email or social) | Werify to Dium | At sign-in |
| Session check | Dium to Werify | Server side, before cookies are set |
What you need
- Members: an email address, nothing else
- Partners: Werify on your site
- Partners: your domain on Dium's redirect allowlist
- Partners: a Flow slug to land members in
Setup
Members just sign in
On Dium's sign-in page, enter an email and the code Werify sends, or use a social account.
Partners: ask us to allow your domain
We add your host to the redirect allowlist and your origin to the CORS list.
Link members to Dium
Send signed-in members to Dium's SSO entry with their Werify session details and the Flow to open.
Dium validates and redirects
Dium checks the session with Werify, sets its cookies, adds the member to the Flow and sends them to the right page.
Troubleshooting
A member lands on the sign-in page instead of the Flow
Werify did not confirm the session, so Dium asks the member to sign in again. Check that the member is signed in on your site and that the session has not expired.
The back link goes to Dium, not our site
Your host is not on the redirect allowlist yet. Dium ignores return addresses it does not know. Write to us to add it.
The member's name or photo looks wrong
Names and photos come from the member's Moat profile, not from Werify. See Moat profiles.
How long does a session last?
Dium sessions last up to 30 days. Session cookies are HttpOnly and Secure.
Try it on a free Flow.
Free while you are under 50 members. Partner features are set up with our team.