Embed sessions API
POST /v1/embed/sessions — open the embeddable editor for one of your end users in their sub-workspace; revoke sessions. Server-side only.
Partner mode only (guide). Call it from your server with your API key.
POST https://api.dcision.io/v1/embed/sessions| Field | Type | |
|---|---|---|
workspace | string or object | ext:<external_id> / the sub-workspace id, or { "external_id", "name", … } to create it on the fly (same fields as POST /v1/workspaces) |
user | object | Required. { "id", "name"?, "email"? } — your end user |
permissions | string[] | Default: all. decisions:read, decisions:write, decisions:deploy, decisions:delete, executions:read, agent |
start_path | string | /decisions (default), /decisions/new or /decisions/{id}[/editor|builder|playground|deploy|executions] |
origins | string[] | A subset of your allowed origins (default: all). Sessions of test keys may also use a local development origin |
locale | string | en, pt, es, ru or zh |
theme | string | light, dark or system |
ttl_seconds | integer | 300–43 200 (default 3 600) |
{
"id": "emb_7Hq2Lm9Xc4Rv1Tz8Wn3B",
"url": "https://app.dcision.io/embed/launch?ticket=emt_…",
"launch_expires_at": "2026-10-09T12:01:00.000Z",
"expires_at": "2026-10-09T13:00:00.000Z",
"permissions": ["decisions:read", "decisions:write", "decisions:deploy", "decisions:delete", "executions:read", "agent"],
"origins": ["https://app.example.com"],
"workspace": { "id": "…", "external_id": "acme", "name": "Acme Inc", "created": false, "…": "…" }
}Load url in an iframe within 60 seconds (it works once) — @dcision/embed does it for you.
Errors: 400 INVALID_REQUEST (an origin outside your allowed list, a bad start_path or permission), 403 FORBIDDEN (partner_disabled, key_without_author), 404 WORKSPACE_NOT_FOUND.
Revoke
| Request | |
|---|---|
DELETE /v1/embed/sessions/{id} | 204: closes one session |
POST /v1/embed/sessions/revoke | { "workspace"?, "user_id"? } → { "revoked": 3 }: closes the live sessions of a sub-workspace and/or one of your users |
A closed or expired session shows "reopen from your app" in the iframe; @dcision/embed opens a new one through your backend.
Sub-workspaces API
POST, GET, PATCH and DELETE /v1/workspaces — partner mode sub-workspaces, one per customer of your app, addressed by your external_id.
Webhook trigger
POST /v1/hooks/{token} — run a deployed decision from a secret URL without an API key, from forms, CRMs, Zapier, n8n, Make or any backend, optionally signed with a whsec_ secret.