Embeddable audit
Install the widget
The embed widget runs entirely as an iframe pointed at your publishable key — there's no JavaScript SDK to install or keep updated. A publishable key is designed to be exposed client-side; it only unlocks the embed audit flow for the origins you've allowed, not your account.
How it works
- Mint a publishable key with POST /v1/embed-configs — there is no widget screen to create one
- One iframe with src pointing at /embed/<key> installs the widget — there is no SDK or script tag
- The widget posts the key, the visitor's origin, and the target URL to POST /v1/embed/audit — the lead then lands in your Lead inbox
Good to know
- Publishable keys are distinct from service-account tokens — they're meant to be public and can only trigger audits, nothing privileged
GET /v1/embed/config?publishableKey=...returns the branding/config the widget renders; an invalid or inactive key returns 401

