Skip to main content

Integrations

Dyma stores third-party credentials in platform_credentials (encrypted at rest). Super admins configure providers in admin.dyma.io → Settings → Credentials. The API never returns decrypted secrets to clients.

Tier 1 platforms​

PlatformProvider keyUsed for
X / TwittertwitterFollow, like, retweet, hashtag tasks
DiscorddiscordJoin server, role verification
TelegramtelegramJoin group/channel, bot start

Discord app credentials​

Configure in admin.dyma.io → Integrations → Discord.

Secret / variable keyRequiredPurpose
clientIdYesDiscord application (OAuth2) client id
clientSecretYesOAuth2 client secret
botTokenYesBot token for guild membership and role checks
publicKeyNoInteractions public key (stored for webhook verify)
botPermissionsNoBot-install OAuth permission bitfield (default 1024 = View Channels)

Empty fields on save keep the currently stored value (partial rotate). Redirect URIs are derived from AUTH_CALLBACK_BASE_URL and shown in Admin (auth callback, link callback, bot-install callback).

EndpointDescription
GET /v1/admin/discord/setupMasked setup info, editable key list, redirect URIs
PUT /v1/admin/credentials/discordCreate or rotate secrets (merged)
POST /v1/admin/credentials/discord/testBot token getMe check

Telegram bot credentials​

Configure in admin.dyma.io → Integrations → Telegram (or Credentials).

Secret keyPurpose
botTokenBotFather token (required)
webhookSecretAuto-generated on webhook register; sent as X-Telegram-Bot-Api-Secret-Token

Metadata may include botUsername, webhookUrl, webhookSetAt.

EndpointDescription
PUT /v1/admin/credentials/telegramSave { botToken }
POST /v1/admin/credentials/telegram/testgetMe connectivity check
POST /v1/admin/telegram/register-webhooksetWebhook to {API_PUBLIC_URL}/v1/telegram/webhook

Set API_PUBLIC_URL on the API so Telegram can reach the webhook (ngrok or production API origin).

Infrastructure providers​

ProviderKeyPurpose
Hetzner Object Storagehetzner_s3Evidence uploads, covers, OG assets
AWS SESaws_sesTransactional email outbox
AI providerai_providerSEO assistant, AI verify tasks
StripestripeSubscriptions and billing webhooks

Admin credential API​

EndpointDescription
GET /v1/admin/credentialsMasked metadata only
PUT /v1/admin/credentials/:providerCreate or rotate secrets
POST /v1/admin/credentials/:provider/testConnectivity check

All writes are recorded in audit_logs.

File uploads (Hetzner S3)​

Client/Studio → POST /v1/files/presign
→ presigned PUT URL (15 min TTL)
→ direct upload to bucket
→ POST /v1/files/:id/confirm

Buckets: dyma-uploads (evidence), dyma-assets (covers, OG).

Project REST verification​

Growth+ plans can register a custom verification endpoint per project. Dyma signs outbound requests with HMAC-SHA256 (X-Dyma-Signature). See Verification.

Realtime​

Redis pub/sub feeds:

  • GET /v1/realtime/submissions (SSE) — submission status for users
  • WebSocket /v1/realtime/studio — moderation queue events
  • WebSocket /v1/realtime/admin — KPI and credential expiry alerts

| npm run test:ses | Validate SES credentials; optional TEST_SES_TO sends multipart HTML sample | | npm run preview:mail | Render all templates to tmp/email-previews/ (run npm run build first) |

Transactional email (AWS SES)​

Mail is sent from dyma-api via the notification_outbox queue and BullMQ worker. Templates are branded HTML + plain text (logo header, footer, security notice).

Environment​

VariablePurpose
AWS_SES_REGIONSES region
AWS_SES_FROMFrom address
AWS_SES_USER_NAMEIAM access key ID
AWS_SES_PASSWORDIAM secret access key
MAIL_LOGO_URLHosted logo image URL
MAIL_SUPPORT_EMAILFooter support address
STUDIO_APP_URL / ADMIN_APP_URL / CLIENT_APP_URLCTA links per app

Template IDs (selection)​

IDUse
studio.signup_verify_otpStudio signup email verification
studio.password_resetStudio forgot password
admin.password_resetAdmin forgot password
notify.claimable_rewardsQuest reward ready (respects prefs)
billing.payment_failedStripe invoice failure
wallet.email_link_otpOn-chain email link verification
quest.email_link_otpVerified Email quest OTP (project + quest context)
studio.moderator_inviteProject moderator invite

Full list: @dyma-io/shared → MAIL_TEMPLATE_IDS.

Client SDK​

OpenAPI is exported to dyma-api/openapi.json. The @dyma-io/api-client package provides a typed fetch wrapper for client, studio, and admin apps.

See also Authentication for Keplr, Google, and Twitter sign-in.

cd dyma-api
npm run generate:api-client