Skip to main content

Clients / Brokers

Clients / brokers manage their organization end users through an embeddable Organization Users panel hosted at https://manage.iccandle.site/.

Platforms create the client account in the admin dashboard, assign a unique identifier, top up the credit bundle, then give the client an embed URL that uses the platform's shared API key plus that identifier.

Production embed:

https://manage.iccandle.site/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER&theme=system&lang=zh&primary=57F63B

Organization Users embed showing credit bundle summary and end-user list for a broker

How it fits together​

  1. In the platform admin dashboard, create the client / broker with a unique identifier and allocate a credit bundle — see Top Up Clients.
  2. Create API key (shared by all clients) — see API Keys.
  3. Give the client the platform apikey and that client's unique identifier. Clients are separated by identifier, not by API key.
  4. The client embeds https://manage.iccandle.site/ in their host app (iframe or dedicated page).
  5. End users are added under that broker by calling seamless auth (sub-org) with the same identifier.
  6. The broker assigns plans to those users in the Organization Users panel.

The panel authenticates from URL search parameters. There is no separate sign-in form inside the embed.

Embed URL parameters​

ParameterRequiredDescription
apikeyYesPlatform API key (one key for the platform). Sent as x-api-key on backend requests.
identifierYesUnique organization / tenant id for this client / broker. Separates clients under the shared key. Spaces are allowed (for example a broker).
langNoUI language: en (default) or zh
themeNoUI theme: light, dark, or system (default)
primaryNoBrand primary color as HEX (RGB, RRGGBB, optional leading #). Invalid values are ignored.

Example iframe:

<iframe
src="https://manage.iccandle.site/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER&theme=system&lang=zh&primary=57F63B"
title="Organization Users"
style="width:100%;height:100%;border:0;"
></iframe>
Protect the embed URL

The apikey value is a secret. Prefer loading the iframe from a page your staff already control, avoid putting live keys in public docs or tickets, and rotate the key if a URL is leaked. The query string is visible in the browser address bar and network logs.

Missing or invalid credentials​

If apikey or identifier is missing or malformed, the panel shows Missing embed credentials and lists each problem (missing / malformed) with a short hint.

Expected shape:

/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER
ParameterValidation
apikey8–128 characters: letters, numbers, _, -, .
identifier2–64 characters: letters, numbers, _, -, ., :, or spaces

What the Organization Users panel shows​

  • Account name (from the organization balance when available, otherwise the identifier)
  • Language and theme controls
  • Refresh

Credit bundle​

Summary cards for Standard, Pro, Expert, and TOTAL:

MetricMeaning
N leftCredits still available to assign
X of Y grantedCredits already assigned to users
Progress barShare of the tier that is granted

Low remaining credits use a warning style; a depleted tier uses a destructive style.

Caption example: 12 of 50 credits assigned to your users.

Users table​

ColumnDescription
UserDisplay name and email
User IDUser id
PlanCurrent plan pill (Standard, Pro, Expert, or No plan)
CreatedCreated date (YYYY-MM-DD)
UpdatedUpdated date (YYYY-MM-DD)

On narrow layouts (under about 760px), users appear as stacked cards instead of a grid.

Search, filter, and sort​

  • Search your users — filters by name, platform name, email, user id, or sub-org name
  • Plan filter — All plans, No plan, or a specific tier
  • Click column headers to sort (User, User ID, Plan, Created, Updated)
  • Pagination with Previous / Next (loads more from the server when needed)

Assign a plan to a user​

  1. Select a user row to open the detail drawer.
  2. Review Current plan (and Last active when available).
  3. Under Assign a plan, choose Standard, Pro, or Expert. Tiers with no credits left are disabled.
  4. Select Review assignment to ….
  5. Confirm in Assign this plan? — the dialog shows the plan change and that one credit is drawn from the bundle.
  6. Select Assign plan.

Rules enforced in the UI:

  • Assigning a paid plan uses one credit of that tier for as long as the user stays on the plan.
  • Tiers with no credits left cannot be selected.
  • If the bundle is fully assigned, the panel tells the client to ask the platform admin to top up.

Platform admin: client / broker records​

In the admin dashboard, platforms also maintain the client / broker account list (create, edit status, allocate bundles). That list is separate from the Organization Users embed, which only shows end users belonging to one client / broker.

See: