Retrieve a widget

View as Markdown
Returns one widget of your workspace. A widget that was deleted, or that belongs to another workspace, returns 404. `api_key` is the stored HMAC digest, not a usable key; the plaintext key was returned once by `POST /api/widgets`. **Idempotency.** Read-only; safe to retry. **Access** - **Required scope:** `read` (or `write`). - **Rate limit:** General API — 120 requests/min per workspace (200 on Growth, 300 on Business, 600 on Enterprise). See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Path parameters

idstringRequiredformat: "uuid"

Widget id. A value that is not a UUID returns 400 Invalid widget ID.

Response

The widget.
dataobject

A web-chat widget configuration. Returned by every /api/widgets endpoint. Field names are snake_case.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error