Let partners keep their PartnerPage listing current without leaving your portal. Your portal shows the PartnerPage listing editor in an iframe, and the partner who is signed in to your portal lands on their own listing with no second login. Works on any page you control: Salesforce Experience Cloud, HubSpot, Impartner, a custom portal, or a plain website with a logged-in area.
Every edit follows your directory's rules: the approval flow (if it is on), fields you manage for your partners, and what partners can and cannot change. Edits show up in the Partner Dashboard and on the public profile exactly like edits made in PartnerPage.
Before you start
A Generic Directory on PartnerPage with the embedded editor switched on by PartnerPage support. The Vendor Dashboard shows an "Embed the listing editor" card under Directory › Integrations once it is on.
Your organization API key (Vendor Dashboard › Developers). The key stays on your server.
Each listing carries an External ID that your portal also knows for the partner (for Salesforce, the partner's Account Id). You can set it when you create listings through the API or the bulk sync.
How it works
Your server asks PartnerPage for a short-lived embed session for the signed-in partner.
Your page renders an iframe with the URL PartnerPage returned.
Inside the iframe, PartnerPage swaps the session for an access token that is tied to that one listing and lives only in memory. If the partner has no PartnerPage account yet, one is created and added to the organization that owns the listing.
The editor loads. Save, validation and approval behave as in the Partner Dashboard.
The session token is stateless and lives 5 minutes; it can be exchanged until it expires, so a reload within that window works. The access token lives 2 hours, after which the editor asks the partner to reload the page (unsaved changes stay on screen).
Step 1: mint an embed session (server side)
POST https://api.partnerpage.io/api/directory/private/v1alpha/directories/{directoryId}/embed-sessions/
Authorization: Token YOUR_ORGANIZATION_API_KEY
Content-Type: application/json
{
"externalId": "0015g00000XyZabAAF",
"email": "jane@partner.com",
"firstName": "Jane",
"lastName": "Doe"
}
Field | Required | Meaning |
| yes | The listing's External ID in this directory. The partner lands on the listing with this value. |
| yes | The portal user's email. It identifies (or creates) the PartnerPage user. |
| no | Used only when the user is created. |
Response 201:
{
"token": "eyJ...",
"expiresAt": "2026-10-08T20:05:00Z",
"embedUrl": "https://directory.partnerpage.io/embed/listing-editor#session=eyJ..."
}
Mint a new session on every page load. Never cache tokens or put them in links you store.
Errors: 400 for a missing or invalid field, 403 when the embedded editor is not enabled for the directory or the key does not belong to the directory's owner.
Step 2: show the editor (page side)
Drop this where the editor should appear and fill in the token from step 1. The script keeps the iframe as tall as its content so there is no inner scrollbar.
<div id="partnerpage-listing-editor"></div>
<script>
(function () {
var token = "EMBED_SESSION_TOKEN"; // minted by your server for the signed-in partner
var origin = "https://directory.partnerpage.io";
var iframe = document.createElement("iframe");
iframe.src = origin + "/embed/listing-editor#session=" + encodeURIComponent(token);
iframe.style.width = "100%";
iframe.style.border = "0";
iframe.style.height = "600px";
iframe.setAttribute("allow", "clipboard-write");
document.getElementById("partnerpage-listing-editor").appendChild(iframe);
window.addEventListener("message", function (event) {
if (event.origin !== origin || !event.data || event.data.type !== "partnerpage-widget-event") return;
if (event.data.event === "onHeightUpdated") iframe.style.height = event.data.payload.height + "px";
});
})();
</script>
Events the iframe posts to your page (event.data.type is always partnerpage-widget-event):
|
| When |
|
| The content height changed. |
| none | The editor opened a modal, showed a toast or scrolled to a validation error. Scroll the iframe's top into view ( |
| none | The editor (or its final error) rendered. Use it to hide a spinner. |
|
| The partner saved the listing or one of its sections. |
The iframe never reads messages from your page.
What the partner sees when something is off
Situation | Message inside the iframe |
No listing carries that External ID | "No listing matches your account. Contact |
Two listings carry the same External ID | "More than one listing matches your account. Contact the directory owner to fix the External ID." |
The email already belongs to another organization on PartnerPage | "Your email belongs to another organization on PartnerPage, so it cannot manage this listing." |
The session token expired or was altered | "This link is no longer valid. Reload the page to open the editor again." |
The access token expired mid-edit | A banner asks to reload; unsaved changes stay on screen until then. |
A partner can never reach a listing other than the one the session was minted for, whatever is changed on your page.
Salesforce Experience Cloud
The PartnerPage for Salesforce package does steps 1 and 2 for you: the partnerPageListingEditor component mints the session with Apex (the API key sits in an External Credential, never in the browser) and renders the iframe. See the package README.md: install, put the API key on the credential principal, set the directory id in the custom metadata record, assign the PartnerPage_Partner_User permission set to your portal profiles, and drag the component onto a page in Experience Builder. The package also ships a CSP Trusted Site for https://directory.partnerpage.io so the iframe is allowed to load.
Keeping synced fields safe
If some fields come from your systems (tier, region, certifications), mark them as managed by the directory in PartnerPage. They show as locked in the embedded editor and the Partner Dashboard, so a partner cannot overwrite what your sync writes.
