Mint a publishable key with POST /v1/embed-configs — there is no widget screen to create one
The widget is configured entirely through the embed-config API; the dashboard has no embed management screen, so a publishable key always comes from POST /v1/embed-configs. A publishable key is meant to be public — unlike a service-account token it carries no account privileges, it only unlocks the embed audit flow for the origins you allow.
1. Create the config#
POST /v1/embed-configs with { name, allowedOrigins, reportDepth, language, dailyAuditLimit }. allowedOrigins is the exact list of site origins (for example https://yoursite.com) that may run audits through this embed. The response returns a freshly generated, unique publishableKey; the key is stored on the config row, so GET /v1/embed-configs and GET /v1/embed-configs/:id can show it again later.
2. Set the guardrails#
dailyAuditLimit— audits per calendar day for this embed; defaults to 100 when omitted. Once reached,POST /v1/embed/auditreturns 429This embed's daily audit limit (N) has been reached.reportDepth—summary(fast, headline scores) orfull(every check); the widget audits at whichever depth the config carries.brandProfileId— optional. When set, the profile'sprimaryColorandlogoUrlare copied into the embed's theme at save time as a one-time snapshot, not a live lookup.copy.headline/copy.subheadline,theme.mode, andlanguage— what the widget renders before a run starts.
3. Rotate or disable#
POST /v1/embed-configs/:id/rotate-key mints a new key and the old snippet stops working immediately, matching how API-key rotation behaves elsewhere. PUT /v1/embed-configs/:id updates origins, quota, theme, or the active flag — an inactive config is indistinguishable from a deleted one to the widget: GET /v1/embed/config and every audit request return 401 Invalid or inactive publishable key.
Expected result#
A config row carrying a publishableKey you can paste into the iframe in Add the iframe, scoped to an allowlisted origin and a daily audit quota.

