Skip to content
DocsGo to Dashboard

Embeddable audit

Install the widget

The embed widget runs entirely as an iframe pointed at your publishable key — there's no JavaScript SDK to install or keep updated. A publishable key is designed to be exposed client-side; it only unlocks the embed audit flow for the origins you've allowed, not your account.

How it works

  • Mint a publishable key with POST /v1/embed-configs — there is no widget screen to create one
  • One iframe with src pointing at /embed/<key> installs the widget — there is no SDK or script tag
  • The widget posts the key, the visitor's origin, and the target URL to POST /v1/embed/audit — the lead then lands in your Lead inbox

Good to know

  • Publishable keys are distinct from service-account tokens — they're meant to be public and can only trigger audits, nothing privileged
  • GET /v1/embed/config?publishableKey=... returns the branding/config the widget renders; an invalid or inactive key returns 401