Delete a widget
Authentication
Path parameters
Widget id. A value that is not a UUID returns 400 Invalid widget ID.
Widget id. A value that is not a UUID returns 400 Invalid widget ID.
Soft-deletes the widget (sets deleted_at and is_active: false). It disappears from
GET /api/widgets, its public embed script returns 404, and runtime calls with its id or API key
return 401 Invalid widget API key. Existing conversations and their messages are kept. There is no
undelete; create a new widget instead (it gets a new id, so the snippet on your site must change).
Side effects. Updates the row, clears the cached widget list, the cached authenticated embed script and the runtime configuration cache, and writes an audit entry.
Consistency. A runtime instance that cached the configuration can keep serving the widget for up to 30 seconds after the delete.
Idempotency. Safe to retry: a repeat returns 404 Widget not found and changes nothing.
Webhook events. audit.log_recorded when you subscribe to it. See Webhooks.
Access
write.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.