Start with one Flow. Grow into many.

What changes as your program grows: embedding, single sign-on, many Flows in one Room, and a security review with real answers.

Three stages, one product

Pick the stage closest to you. Every stage runs the same Dium.

One Flow, under 50 members

Prove the idea with a pilot group before anyone signs anything.

  • Free plan, no card
  • Every Wave type, live sessions, roles and search
  • Help center and email support
  • Sign-in by email code or social account

Dium inside your own website

Each community in Dium is a Flow. Partners mount their Flows under a path on their own domain, such as /community/. Members stay on your site and see your name.

  • A small server file on your host loads Dium at the path you choose
  • Your backend asks Dium for a one-time sign-in token that expires in five minutes
  • API keys are scoped, so a key can be limited to actions like creating sponsor Pages
  • Create Flows, sessions and Pages from your own systems, without duplicates on retry

Developer overview

Server-to-server sign-in token
curl -X POST https://dium.io/api/auth.php \
  -H "Content-Type: application/json" \
  -H "X-Api-Key: $DIUM_PARTNER_KEY" \
  -d '{"action": "issue_token",
       "email": "[email protected]",
       "name": "Sam Lee"}'

# Response
# {"success": true, "token": "<48 hex>",
#  "expires_in": 300}
# Then send the browser to
# /home/autologin.php?token=...

Sign-in and structure

Single sign-on

SSO runs through Werify, the sign-in service Dium shares with its sister products. Tell us your identity provider and we will confirm the fit before you sign.

One profile per person

Names and photos come from each member's Moat profile, so people keep one identity across every Flow they join.

Many Flows, one Room

Group Flows by program, region or year. Members and direct messages carry across the Room; Waves and moderators stay per Flow.

For your security review

Short, factual answers. Longer ones are on the linked pages.

Sessions and cookies

Auth cookies are Secure, HttpOnly and SameSite=Lax. The app uses CSRF tokens.

Partner access

Allowed origins are listed per partner. API keys are matched in constant time and limited by scope.

Abuse limits

Per-IP rate limits on busy actions, for example 30 replies or 30 direct messages a minute and 10 reports a minute.

Browser hardening

A strict content security policy and X-Frame-Options DENY on the app shell.

What we do not hold

No SOC 2, ISO 27001 or other certifications. We do not offer a choice of data region today.

Support by stage

What each stage includes today. We will not promise response times beyond what the SLA page states.
What you getFreeProWritten agreement
Help center and email
Priority support
Setup help for embedding and SSO
Service level termsSee /sla/
Invoices and a security questionnaire

Tell us what your program needs to pass.

Bring your security questions and your member numbers. We will answer both in writing.