New:Socket for Asana Is Now Available.Learn more
Sign In

@dodomain/connect

Package Overview
Dependencies
Maintainers
1
Versions
6
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@dodomain/connect

Official browser widget for DoDomain — opens the hosted domain-connect flow in a modal iframe and relays its lifecycle events.

Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
832
834.83%
Maintainers
1
Weekly downloads
 
Created
Source

@dodomain/connect

Embeddable browser widget for DoDomain. Opens the hosted connect flow in a modal iframe and relays its lifecycle events back to your app. Pairs with @dodomain/node, which mints the session token on your server.

Install

npm install @dodomain/connect
# or: pnpm add @dodomain/connect · yarn add @dodomain/connect

Zero runtime dependencies, ~3KB browser bundle (dual ESM+CJS + self-contained .d.ts; the bundle stays zod-free — see test/build.smoke.test.ts).

Usage

import { showDoDomain } from "@dodomain/connect";

// token comes from your server: POST /api/v1/sessions via @dodomain/node
const { token } = await fetch("/my-api/domain-session").then((r) => r.json());

const handle = showDoDomain({
  token,
  onVerified: ({ domain }) => {
    console.log("connected:", domain);
    location.reload();
  },
  onClose: () => console.log("user closed the modal"),
  onError: (err) => {
    // { type: "load-timeout" } | { type: "load-error" } | { type: "session-error", code }
    console.error("connect flow failed to load:", err);
  },
});

// handle.close() to dismiss it programmatically

API

showDoDomain(options) → { close }

OptionTypeNotes
tokenstringRequired. Session token (dd_sess_…) from POST /api/v1/sessions.
baseUrlstringDoDomain origin. Defaults to https://app.dodomain.io.
onVerified(detail: { domain?: string }) => voidFires when the domain verifies.
onClose() => voidFires when the modal is dismissed (backdrop click or in-flow close).
onError(detail: DoDomainWidgetError) => voidFires when the flow fails to load or reports a session error — see below. Absent by default (previously: silent).
loadTimeoutMsnumberHow long to wait for the hosted flow's load handshake before treating the embed as failed. Default 15000.

Returns a handle with close(). Messages from the iframe are origin-checked against baseUrl, so only the hosted flow can trigger callbacks. Must run in a browser.

onErrorDoDomainWidgetError

A cross-origin iframe's HTTP 404/500 doesn't fire onerror or expose readable content, so a broken embed used to be entirely silent. onError now fires with one of:

  • { type: "load-timeout" } — no load handshake arrived within loadTimeoutMs (covers a 404, DNS failure, or a hang — anything that never gets far enough to run the hosted flow's own JS).
  • { type: "load-error" } — the iframe's own error event fired (best-effort; rarely fires for a cross-origin navigation, but free to listen for).
  • { type: "session-error", code: string } — the flow loaded but reported a failure (e.g. a verify() call failing mid-flow). code matches the same vocabulary the hosted page's own in-page error banner uses (expired, not_found, invalid_request, internal).

See src/index.ts for the implementation.

Keywords

dodomain

FAQs

Package last updated on 31 Jul 2026

Related posts