DocsAPI reference

Get embed

The snippet a customer pastes, in two forms.

get/api/agents/{agent_id}/embed
Authentication
Bearer token
Retries
Safe to repeat
Body
None
Version
2026-09-03

snippet is the one almost everybody wants: a stable URL that picks up every widget improvement without them touching their HTML again.

pinned_snippet is for the customer whose change-control process forbids a third-party script that can change under them - which is most enterprises, and the question arrives during a security review rather than during a trial. It names the content-hashed build and carries an integrity hash, so the browser refuses to execute anything but the exact bytes that were reviewed.

Pinning is offered, never defaulted. A pinned embed stops receiving fixes, including security ones, until somebody edits their page - so it has to be a decision the customer makes rather than one we make for them.

Path parameters#

  • agent_idstringrequired

Responses#

  • 200OKapplication/json

    object

    5 response headers
    RateLimit-Limit

    Requests permitted in the current window.

    RateLimit-Remaining

    Requests left in the current window. Back off before it reaches 0.

    RateLimit-Reset

    Seconds until the current window resets.

    X-API-Version

    The dated version of the API contract that served this response, e.g. 2026-09-03. Pin against it; it changes only when a response shape changes incompatibly.

    X-Request-ID

    Quote this in a support request to identify the call.

  • 422Validation error

    The shared error envelope, served as application/problem+json with error.code set to validation_error. Its details name each field that failed and why.

Errors#

Failures use one envelope on every endpoint, described in Retries, versioning and limits. The codes you are most likely to meet here:

  • validation_error · 422 — The payload was well-formed JSON but failed schema validation.
  • unauthenticated · 401 — The request carried no API key, or one the API could not verify.
  • forbidden · 403 — The key is valid, but it is not allowed to do this — either the scope is missing or the resource belongs to another workspace.
  • rate_limited · 429 — Too many requests in the current window. The limit is per workspace, and some endpoints add a per-agent limit on top.

More Agents endpoints#

Something unclear or missing? Tell us and we’ll fix it.