Security model
- Treat the widget public ID as public, not as an API secret.
- Keep API keys out of browser JavaScript.
- Configure allowed origins before embedding.
- Never expose private agent configuration or webhook secrets in widget responses.
Runtime endpoints
Embed checklist
- Select a published voice agent.
- Create a widget and configure its origin allowlist.
- Fetch the generated embed configuration.
- Test from an allowed origin.
- Confirm calls, rate limits, and failures before production rollout.