Werify SSO: one sign-in for members and partners

Every Dium sign-in runs through Werify. Partners with Werify on their own site can send members into Dium already signed in.

CategorySign-in and identity
DirectionWerify to Dium
PlanBuilt in for members; partner SSO with our team
Set up byNobody for members; Dium and you for partners

What it does

Members sign in with an emailed code or a social account through the Werify widget. There is no Dium password to forget.

For partners, Werify SSO lets a member who is signed in on your site open Dium and land signed in. Dium checks the session with Werify on its own server before it trusts it, and only redirects back to hosts on its allowlist.

Werify is also the payment provider behind Pro plans (Werify Paywall), but that is separate from sign-in.

What data moves

DataDirectionWhen
Email addressWerify to DiumAt sign-in
Werify user keyWerify to DiumAt sign-in
Moat public keyWerify to DiumAt sign-in, links the member to their profile
Sign-in method (email or social)Werify to DiumAt sign-in
Session checkDium to WerifyServer side, before cookies are set

What you need

  • Members: an email address, nothing else
  • Partners: Werify on your site
  • Partners: your domain on Dium's redirect allowlist
  • Partners: a Flow slug to land members in

Setup

  1. Members just sign in

    On Dium's sign-in page, enter an email and the code Werify sends, or use a social account.

  2. Partners: ask us to allow your domain

    We add your host to the redirect allowlist and your origin to the CORS list.

  3. Link members to Dium

    Send signed-in members to Dium's SSO entry with their Werify session details and the Flow to open.

  4. Dium validates and redirects

    Dium checks the session with Werify, sets its cookies, adds the member to the Flow and sends them to the right page.

Troubleshooting

A member lands on the sign-in page instead of the Flow

Werify did not confirm the session, so Dium asks the member to sign in again. Check that the member is signed in on your site and that the session has not expired.

The back link goes to Dium, not our site

Your host is not on the redirect allowlist yet. Dium ignores return addresses it does not know. Write to us to add it.

The member's name or photo looks wrong

Names and photos come from the member's Moat profile, not from Werify. See Moat profiles.

How long does a session last?

Dium sessions last up to 30 days. Session cookies are HttpOnly and Secure.

Try it on a free Flow.

Free while you are under 50 members. Partner features are set up with our team.