@karzoun/dashboard-sdk is a lightweight client for dashboard panel apps embedded in the Karzoun inbox. Your page loads in a sandboxed iframe; the SDK talks to the host over postMessage. Credentials for linked MiniApps never enter the iframe.
Full API reference, protocol notes, and working HTML examples live in the public repo: KarzounApps/dashboard-sdk.
Prerequisites
1
Install a MiniApp (optional but typical)
In Karzoun: Settings → Applications. Connect credentials for the platform you need (for example Shopify, Zid, or Salla). The MiniApp defines named actions your panel can call.
2
Host your panel page
Deploy any static page (single HTML file or a small frontend) to a public URL — Vercel, Cloudflare Pages, Netlify, your own server, or
localhost while developing.3
Declare or create a Dashboard App
From a MiniApp: publishers can declare panels in
definition.dashboardApps[] (key, name, iframeUrl, …). After the MiniApp is installed, tenants open Settings → Applications → and choose which panels to Install. Nothing is auto-installed.Custom: create a panel manually under Developer → Dashboard Apps with an iframe URL, optional MiniApp link, and assignees.Karzoun-hosted HTML upload for panels is planned for a later phase. Phase 1 uses external
iframeUrl only.Install
Quick start
What works today
Core API
Lifecycle
createDashboard(options?)— options:heartbeatInterval,actionTimeout,debug,onErrorinit({ onReady })— sendsapp_ready;onReadyruns after conversation data arrives (or after a short timeout)destroy()— remove listeners and pending requests
Context
getConversation()/onConversationUpdate(cb)getCustomerContext()/onCustomerContextUpdate(cb)
CustomerContext shape:
Actions
getActions()/getCapabilities()executeAction(actionName, formInput?)— promise always resolves; checkresult.success
AUTH_EXPIRED, RATE_LIMITED, ACTION_NOT_FOUND, VALIDATION_ERROR, EXTERNAL_API_ERROR, INTERNAL_ERROR, NOT_INSTALLED, NOT_CONFIGURED.
How it fits together
HTML-only panel
A dashboard app does not need a framework. A single HTML file that imports the SDK (bundler or ESM) is enough — host that file and paste its URL into Iframe URL. See the Shopify and Zid examples in the dashboard-sdk repo.Security
- Credentials stay server-side; the iframe only sends action names and form values
- Host validates
event.originagainst the registered iframe URL - Iframe sandbox includes scripts, same-origin, forms, and popups (see host implementation for the exact attribute string)
Related
- MiniApps — define the actions your panel calls
- GraphQL API — server-side alternative to iframe panels
- Help Center: Dashboard apps — admin setup (Arabic)