Professional identity, as an API.
Let people bring their Moat page into your app. Sign them in, show their card, and hear about every change.
<script src="https://moat.page/profile/widget.js" defer></script>
<div class="moat-widget"
data-public-key="PUBLIC_KEY"
data-level="public"
data-theme="light"></div>curl -X POST https://moat.page/profile/api/has_profile \ -H "X-API-Key: $MOAT_XSITE_API_KEY" \ -d "[email protected]"
$ch = curl_init('https://moat.page/profile/api/create_profile');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => ['X-API-Key: ' . MOAT_XSITE_API_KEY],
CURLOPT_POSTFIELDS => http_build_query(['email' => $email]),
]);
$moat = json_decode(curl_exec($ch), true); // ['public_key' => ...]const res = await fetch("https://moat.page/profile/api/create_profile", {
method: "POST",
headers: { "X-API-Key": process.env.MOAT_XSITE_API_KEY },
body: new URLSearchParams({ email }),
});
const { public_key, created } = await res.json();Running in production on
Four building blocks. Use one or all.
Identity API
Check whether a user has a page, get or create one on sign-in, update fields, and query directories of people, companies and services.
API referenceWidgets and editor
Drop-in profile, company and service views, directory lists, and an in-place editor that saves straight to Moat.
Widget docsSign-in
Email-code sign-in through Werify, then a server-to-server call that links the person to their Moat page.
Sign-in guideWebhooks
HMAC-signed events when a page is updated, deleted, suspended or unlinked from your app.
Webhook docsAn integration, start to finish.
The same four steps every partner app follows. The quickstart walks through each one with the exact request and response.
Sign in
Your user verifies their email with Werify. Your server confirms the result.
Your server is the trust boundary
Link
Call create_profile with their email. Store the public_key it returns.
Get-or-create, safe to repeat
Show and listen
Render their card with the widget, and verify the signed webhooks Moat sends when it changes.
HMAC-SHA256 signatures
Secure by default.
Moat carries people's professional identity, so the defaults are strict and the rules are written down.
- Keys stay on servers. Browsers only ever use a person's public key.
- Contact details need a key. Email and phone are returned only to requests signed with a partner key or the person's private key.
- Signed events. JSON webhooks carry an HMAC-SHA256 signature you check with a constant-time compare.
- Allowlisted origins. Cross-site requests work only from domains added for your app.
- Rate-limited public reads. 60 requests per minute per IP on the public widget endpoint.
- Short-lived editor grants. In-place editor saves are signed on your server and expire after four hours.
Documentation
Quickstart
Five steps from API key to a verified webhook.
Open ReferenceAPI reference
Every endpoint, parameter and error.
Open Front endWidgets and editor
Embeds, levels, theming and the JS API.
Open EventsWebhooks
Events, payloads and signature checks.
Open AuthSign-in (SSO)
Werify sign-in and profile linking.
Open LegalPartner terms
Data use, security and deletion duties.
OpenDeveloper questions.
How do I get an API key?
Keys are issued per partner app. Tell us about your app, and we'll set up your key, webhook secret and allowed domains.
Can I show a card without a key?
Yes. Public cards need only the person's public key, which is safe to put in a browser. Keys are for server calls and for contact details.
Do you support companies and services too?
Yes. Companies and services have their own get, create, update and directory endpoints, and their own embeddable views.
What does it cost?
Partner access is arranged per app during early access.
Bring Moat into your app.
Tell us what you're building. We'll set up keys, webhooks and your domains.