Skip to main content
@karzoun/dashboard-sdk is a lightweight client for dashboard panel apps embedded in the Karzoun inbox. Your page loads in a sandboxed iframe; the SDK talks to the host over postMessage. Credentials for linked MiniApps never enter the iframe.
Full API reference, protocol notes, and working HTML examples live in the public repo: KarzounApps/dashboard-sdk.

Prerequisites

1

Install a MiniApp (optional but typical)

In Karzoun: Settings → Applications. Connect credentials for the platform you need (for example Shopify, Zid, or Salla). The MiniApp defines named actions your panel can call.
2

Host your panel page

Deploy any static page (single HTML file or a small frontend) to a public URL — Vercel, Cloudflare Pages, Netlify, your own server, or localhost while developing.
3

Declare or create a Dashboard App

From a MiniApp: publishers can declare panels in definition.dashboardApps[] (key, name, iframeUrl, …). After the MiniApp is installed, tenants open Settings → Applications → and choose which panels to Install. Nothing is auto-installed.Custom: create a panel manually under Developer → Dashboard Apps with an iframe URL, optional MiniApp link, and assignees.
Karzoun-hosted HTML upload for panels is planned for a later phase. Phase 1 uses external iframeUrl only.

Install

If the package is not yet available on the npm registry, install from GitHub:
For a single HTML file without a bundler, use the ESM CDN path from the package README once the package is published.

Quick start

What works today

Core API

Lifecycle

  • createDashboard(options?) — options: heartbeatInterval, actionTimeout, debug, onError
  • init({ onReady }) — sends app_ready; onReady runs after conversation data arrives (or after a short timeout)
  • destroy() — remove listeners and pending requests

Context

  • getConversation() / onConversationUpdate(cb)
  • getCustomerContext() / onCustomerContextUpdate(cb)
CustomerContext shape:

Actions

  • getActions() / getCapabilities()
  • executeAction(actionName, formInput?) — promise always resolves; check result.success
Common error codes: AUTH_EXPIRED, RATE_LIMITED, ACTION_NOT_FOUND, VALIDATION_ERROR, EXTERNAL_API_ERROR, INTERNAL_ERROR, NOT_INSTALLED, NOT_CONFIGURED.

How it fits together

Admins can allowlist actions per dashboard app. The host rate-limits action calls (default 30/min per session).

HTML-only panel

A dashboard app does not need a framework. A single HTML file that imports the SDK (bundler or ESM) is enough — host that file and paste its URL into Iframe URL. See the Shopify and Zid examples in the dashboard-sdk repo.

Security

  • Credentials stay server-side; the iframe only sends action names and form values
  • Host validates event.origin against the registered iframe URL
  • Iframe sandbox includes scripts, same-origin, forms, and popups (see host implementation for the exact attribute string)
Last modified on August 12, 2026