If you have a paid API subscription, the widget uses a site registration model to keep your API key secure:
- You register your domain in your developer dashboard and link it to your API key.
- The widget only sends your public site ID (safe to embed in HTML).
- Our server validates that the request comes from your registered domain, then uses your API key server-side.
- Your API key never appears in the browser, page source, or network requests.