Skip to content

Conversation

@stiller
Copy link

@stiller stiller commented Oct 17, 2022

No description provided.

@adriaandotcom
Copy link
Contributor

Thanks for your PR! Appreciate it.

Not 100% sure we can want to push people in using their API key in the front end. Maybe we should add an API key for the embed script per website. What do you think @stiller?

@stiller
Copy link
Author

stiller commented Oct 18, 2022

I agree. I was planning on using this on the admin side of a CMS, so all users would be privileged anyway. It would definitely help to have a read-only API key per website. An even better solution would be a minimal server-side client that would generate a token per request that the JS client can use - a bit like how Stripe handles checkouts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants