window.parent.postMessage, using the messages in the table. Analytics events and host-rendered dialogs travel over a different channel, the host bridge.
Fanvue accepts a message only when event.source is the iframe and the origin is the launched app origin. It replies to that origin, and drops malformed messages silently.
Messages
Every message carries its
type as a field. The other fields:
tokenis the opaque request token fromPOST /experiences/request-token.clientReferenceIdis up to 200 characters, and is echoed on the result and on the settled-purchase webhook.amountMinorUnitsandpriceCentsare USD cents.reasonis set on acancelledpublish or unpublish result when the ending was not the creator’s choice; the values are on Publish experiences.
purchase-request never carries an amount, because Fanvue resolves the price from the catalogue. A price-result of saved without amountMinorUnits means the creator withdrew the action.
Rate limits
Each fan bridge has its own token bucket with a burst of 3 and a refill of 10 per minute. A purchase, top-up or consent request over budget answersfailed. A close request over budget is ignored.
Origin checks
Validateevent.origin on every reply with isFanvueOrigin, which requires the protocol https: and the host fanvue.com or a *.fanvue.com subdomain.
Fanvue posts replies to the vouched origin of your registered surface URL, so the browser already refuses delivery anywhere else. The check defends against a sibling frame on a shared origin.
SDK coverage
The SDK shipsisFanvueOrigin, plus schemas and type guards for the four publish and unpublish messages: PublishRequestMessageSchema, PublishResultMessageSchema, UnpublishRequestMessageSchema, UnpublishResultMessageSchema, isPublishResultMessage and isUnpublishResultMessage. Price, purchase, top-up, consent and close have no SDK helpers, so post those by hand.
Listener
One listener can validate the origin and dispatch ontype.
One request per type
One request per type