Authentication and Headers
Widget-Side Endpoints
Widget endpoints authenticate using:
X-Widget-Publishable-Key: requiredX-Visitor-Id: required for chat and leads
When domain allowlist is enabled, origin/referer must match an allowed domain.
Common Response Headers
X-Conversation-Id: conversation session identifierX-Assistant-Message-Id: stored assistant message idX-Visitor-Id: canonical visitor idx-rag-context: URL-encoded JSON source summaries
Rate Limit Headers
On 429, responses include:
Retry-AfterX-RateLimit-ScopeX-RateLimit-LimitX-RateLimit-RemainingX-RateLimit-Reset
Last updated on