Retrieve a widget
Authentication
Path parameters
Widget id. A value that is not a UUID returns 400 Invalid widget ID.
Response
A web-chat widget configuration. Returned by every /api/widgets endpoint. Field names are snake_case.
Widget id. A value that is not a UUID returns 400 Invalid widget ID.
A web-chat widget configuration. Returned by every /api/widgets endpoint. Field names are snake_case.
Returns one widget of your workspace. A widget that was deleted, or that belongs to another workspace, returns 404.
api_key is the stored HMAC digest, not a usable key; the plaintext key was returned once by
POST /api/widgets.
Idempotency. Read-only; safe to retry.
Access
read (or write).Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.