Skip to main content
Widget runtime endpoints are intentionally unauthenticated so a browser visitor can load a configured widget. Management endpoints remain API-key protected.

Security model

  • Treat the widget public ID as public, not as an API secret.
  • Keep API keys out of browser JavaScript.
  • Configure allowed origins before embedding.
  • Never expose private agent configuration or webhook secrets in widget responses.

Runtime endpoints

The runtime call endpoint starts a two-way WebRTC browser call with the widget’s voice agent. For step-by-step setup, the generated embed code, and a custom browser client example, see WebRTC browser calls.

Embed checklist

  1. Select a published voice agent.
  2. Create a widget and configure its origin allowlist.
  3. Fetch the generated embed configuration.
  4. Test from an allowed origin.
  5. Confirm calls, rate limits, and failures before production rollout.