Check that a chat site may appear on this page, and fetch its appearance
The widget's first call. Answers whether the requesting origin is allowed, records the install (the panel shows 'seen on your website'), and returns the greeting, title, accent colour and the branding line. Called with the page's Origin; a server-side call without one is refused with origin_not_allowed.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
| X-API-Version | header | string ∈ "1" | Pin the API version the request is written against. Optional: without it the current version (1) answers. A version that does not exist is refused with 400 unsupported_version rather than answered by another version. |
| k* | query | string | The site's public key from the panel. Not a secret: it ships in the page's HTML. |
| Origin* | header | string (uri) | The page's origin, set by the browser. Must be on the site's allowed-domains list. |
Responses
- 200The origin is allowed; the widget may draw itself.→ ChatHello (application/json)headers: X-API-Version, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Deprecation, Sunset
- 400The key is missing, or X-API-Version names a version that does not exist.→ Error (application/json)headers: X-API-Version, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Deprecation, Sunset
- 403The page's origin is not allowed for this site. The response echoes the origin so the exact string can be approved in the panel.→ Error (application/json)headers: X-API-Version, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Deprecation, Sunset
- 404No active site has this key (the same answer for a paused site, so keys cannot be enumerated).→ Error (application/json)headers: X-API-Version, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Deprecation, Sunset
- 429Rate limited.→ Error (application/json)headers: X-API-Version, RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset, Deprecation, Sunset, Retry-After