Security & Troubleshooting
Protect account and buyer data, understand current security limitations, and follow safe recovery steps.
On this page
Protect seller and provider access
- Treat every Diem email magic link like a password. Never forward it or paste the full URL into a support message.
- Sign out and clear site data after using a shared device.
- Invite only trusted workspace members; current role labels are not a complete authorization barrier.
- Enter provider passwords and verification codes only in the intended provider connector.
- Review the connected Instagram account, Stripe account, and workspace before publishing.
Protect buyer confirmations and content
- Never publish a buyer confirmation code, receipt URL, guest token, or signed content URL.
- Do not ask a buyer to email a full card number, security code, password, or provider verification code.
- Use only trusted HTTPS destinations for manual links.
- Assume a published Link Page profile, image, social link, section, and listing summary are public.
- Treat view-only content as a viewing convenience, not DRM.
- Confirm uncertain payments in Stripe before asking a buyer to retry.
Known security limitations
- Immediate guest access is a short-lived capability scoped to one purchase and confirmation; it is not a general buyer session.
- Later access requires a one-time magic link for the exact checkout account, and the authenticated account must own the confirmation.
- A confirmation code alone does not grant access, but receipt, guest-capability, and signed asset URLs must still be kept private.
- View Only uses short-lived signed URLs and entitlement checks, but browser-visible content can still be copied or captured.
- A refund blocks future resource entitlement checks but cannot recall an external URL, downloaded file, provider admission, or signed URL already delivered.
- Provider fulfillment can require manual reconciliation when a safe retry or provider cancellation is unavailable. Full-refund, full-dispute, reversal, clawback, and enabled payout workers use bounded automatic retries; partial, overlapping, ambiguous, or exhausted states require operator review.
- One-time card checkout can attach and set a payment method as default without clear consent copy.
These public guides intentionally describe impact and safe behavior without publishing instructions that could be used to exploit the system.
Common problems and safe next steps
| Problem | Safe next step |
|---|---|
| Magic link is expired or already used | Return to Sign in and request a new link. Open only the newest email. |
| Instagram approval is pending | Wait for approval; the displayed timing is not a guaranteed service level. |
| Instagram returns without connecting | Open Settings, verify the account, retry once, and capture the non-sensitive error text. |
| Provider verification code is rejected | Wait for the resend countdown, request a new provider code, and enter only the newest one. |
| Imported events are missing | Refresh the provider and Listings, then compare against the source. Posh manual refresh currently has a known limitation. |
| Media conversion fails | Convert MOV to MP4 and retry. Keep the browser open until upload and publishing finish. |
| Link Page says Error saving | Do not publish. Complete every manual link, retry, and wait for Saved. |
| Published Link Page says temporarily unavailable | No checkout starts from that error state. Retry later before changing the username; a true missing or unpublished page uses a different result. |
| Dashboard or Audience is unexpectedly empty | Refresh and verify another data source because failures can appear as zero or empty. |
| A purchase is not visible on another device | Request a new magic link for the exact email entered at checkout. Buyers do not need to pre-register; Diem created or reused that account and assigned the purchase to it. |
| Checkout says the seller cannot accept payment | Stop retrying. The seller must finish Stripe onboarding and become ready for charges and payouts. |
| Payment or fulfillment is uncertain | Do not retry payment blindly. Reconcile Stripe, Diem, email, and provider state. |
| A refunded buyer can still open something already delivered | Confirm the refund revoked future resource entitlement, then rotate any external destination. Downloaded files and still-valid signed URLs cannot be recalled. Remove issued tickets or guest-list entries directly in the event provider before closing reconciliation. |
Report a security or payment incident
Reduce exposure
Unpublish the affected Link Page or remove the affected listing when doing so will not destroy evidence. The public renderer can remain cached for about 60 seconds; rotate or remove sensitive content at its source when necessary.
Preserve safe context
Record the approximate time, seller workspace, public offer title, affected provider, and visible error. Do not copy tokens, full request bodies, full card data, or signed URLs.
Check money movement
For payment incidents, review Stripe before retrying, refunding, or manually fulfilling.
Rotate third-party access
If a provider credential may be exposed, rotate it with that provider and ask Diem support to remove or update the connection.
Contact Diem
Email support@withdiem.com with the safe context and mark urgent security or payment incidents clearly.