iframe inside the main Exode app. A school connects
it through a custom page. The SDK provides two-way communication between the
mini app and the host via postMessage and helps you verify the signature of user data on your server.
Architecture
The host side of the bridge is implemented inside the main Exode app. The guest side (what the MiniApp developer includes) is
@exode-team/sdk/miniapp.Lifecycle
1
Loading the iframe
The main app opens the MiniApp by URL in an
iframe and appends signed user data to the address —
#exodeInitData=... (see Init Data).2
Handshake
The MiniApp calls
app.init() and sends its appId to the host. The host checks the message origin (for custom
pages, the origin of the address from “App URL (iframe)”; appId can be anything in this case) and returns the context
(user, school, theme, config).3
Operation
The MiniApp sends commands (
navigate, showSnackbar, …). The host pushes events (theme:changed, user:updated, …).4
Shutdown
On unmount, the MiniApp calls
app.destroy() — the bridge closes its listeners and releases resources.What is available to a MiniApp
Host context
Host context
- User profile (name, avatar, email, role, language)
- School object
- Current theme (
light/dark) - Platform (
web/native) and device (isDesktop/isMobile)
Commands to the host
Commands to the host
- Navigation within the main app
- Showing snackbar notifications
- Controlling tabbar / header visibility
- Closing the mini app
Reactive events
Reactive events
- Theme, user, school and config changes
- Host route changes
- iframe visibility changes
What’s next
ExodeMiniApp client
Vanilla JS client: init, route, ui, events.
Context and types
MiniAppContext structure, event and command types.
React hooks
Provider and reactive hooks for React apps.
Init Data
Signed user data and how to verify it on your server.
Telegram Mini App
Auto sign-in via the
___uat parameter.Updated: 2026-09-25 14:33 UTC