Get embed
The snippet a customer pastes, in two forms.
- Authentication
- Bearer token
- Retries
- Safe to repeat
- Body
- None
- Version
- 2026-09-03
snippet is the one almost everybody wants: a stable URL that picks up every widget improvement without them touching their HTML again.
pinned_snippet is for the customer whose change-control process forbids a third-party script that can change under them - which is most enterprises, and the question arrives during a security review rather than during a trial. It names the content-hashed build and carries an integrity hash, so the browser refuses to execute anything but the exact bytes that were reviewed.
Pinning is offered, never defaulted. A pinned embed stops receiving fixes, including security ones, until somebody edits their page - so it has to be a decision the customer makes rather than one we make for them.
Path parameters#
Responses#
Errors#
Failures use one envelope on every endpoint, described in Retries, versioning and limits. The codes you are most likely to meet here:
validation_error· 422 — The payload was well-formed JSON but failed schema validation.unauthenticated· 401 — The request carried no API key, or one the API could not verify.forbidden· 403 — The key is valid, but it is not allowed to do this — either the scope is missing or the resource belongs to another workspace.rate_limited· 429 — Too many requests in the current window. The limit is per workspace, and some endpoints add a per-agent limit on top.
More Agents endpoints#
Something unclear or missing? Tell us and we’ll fix it.