Skip to content
DocsGo to Dashboard
Install the widget

Mint a publishable key with POST /v1/embed-configs — there is no widget screen to create one

The widget is configured entirely through the embed-config API; the dashboard has no embed management screen, so a publishable key always comes from POST /v1/embed-configs. A publishable key is meant to be public — unlike a service-account token it carries no account privileges, it only unlocks the embed audit flow for the origins you allow.

1. Create the config#

POST /v1/embed-configs with { name, allowedOrigins, reportDepth, language, dailyAuditLimit }. allowedOrigins is the exact list of site origins (for example https://yoursite.com) that may run audits through this embed. The response returns a freshly generated, unique publishableKey; the key is stored on the config row, so GET /v1/embed-configs and GET /v1/embed-configs/:id can show it again later.

2. Set the guardrails#

  • dailyAuditLimit — audits per calendar day for this embed; defaults to 100 when omitted. Once reached, POST /v1/embed/audit returns 429 This embed's daily audit limit (N) has been reached.
  • reportDepth — summary (fast, headline scores) or full (every check); the widget audits at whichever depth the config carries.
  • brandProfileId — optional. When set, the profile's primaryColor and logoUrl are copied into the embed's theme at save time as a one-time snapshot, not a live lookup.
  • copy.headline / copy.subheadline, theme.mode, and language — what the widget renders before a run starts.

3. Rotate or disable#

POST /v1/embed-configs/:id/rotate-key mints a new key and the old snippet stops working immediately, matching how API-key rotation behaves elsewhere. PUT /v1/embed-configs/:id updates origins, quota, theme, or the active flag — an inactive config is indistinguishable from a deleted one to the widget: GET /v1/embed/config and every audit request return 401 Invalid or inactive publishable key.

Expected result#

A config row carrying a publishableKey you can paste into the iframe in Add the iframe, scoped to an allowlisted origin and a daily audit quota.

Back to Install the widget