Product

How it works Widgets Compare HAPI score

Who it's for

Professionals Companies Services

More

Developers Pricing Journal
Claim your pageSign in

Professional identity, as an API.

Let people bring their Moat page into your app. Sign them in, show their card, and hear about every change.

<script src="https://moat.page/profile/widget.js" defer></script>

<div class="moat-widget"
     data-public-key="PUBLIC_KEY"
     data-level="public"
     data-theme="light"></div>

Running in production on

ClubDiumjoqewent

An integration, start to finish.

The same four steps every partner app follows. The quickstart walks through each one with the exact request and response.

Sign in

Your user verifies their email with Werify. Your server confirms the result.

Your server is the trust boundary

Link

Call create_profile with their email. Store the public_key it returns.

Get-or-create, safe to repeat

Show and listen

Render their card with the widget, and verify the signed webhooks Moat sends when it changes.

HMAC-SHA256 signatures

Secure by default.

Moat carries people's professional identity, so the defaults are strict and the rules are written down.

  • Keys stay on servers. Browsers only ever use a person's public key.
  • Contact details need a key. Email and phone are returned only to requests signed with a partner key or the person's private key.
  • Signed events. JSON webhooks carry an HMAC-SHA256 signature you check with a constant-time compare.
  • Allowlisted origins. Cross-site requests work only from domains added for your app.
  • Rate-limited public reads. 60 requests per minute per IP on the public widget endpoint.
  • Short-lived editor grants. In-place editor saves are signed on your server and expire after four hours.

Developer questions.

How do I get an API key?

Keys are issued per partner app. Tell us about your app, and we'll set up your key, webhook secret and allowed domains.

Can I show a card without a key?

Yes. Public cards need only the person's public key, which is safe to put in a browser. Keys are for server calls and for contact details.

Do you support companies and services too?

Yes. Companies and services have their own get, create, update and directory endpoints, and their own embeddable views.

What does it cost?

Partner access is arranged per app during early access.

Bring Moat into your app.

Tell us what you're building. We'll set up keys, webhooks and your domains.