Public key and visitor data
The public key pub_live_... identifies a project. It is included in your website code and is not a password. In “Widget integration”, enter the exact HTTPS origin of each live website, such as https://app.example.com. An origin does not include the page path or parameters; a different domain or port requires a separate entry. Origin validation restricts browser requests but does not replace authentication on your server.
In “Only with consent” mode, do not pass user data to identify or setTraits before the user actually consents in your banner. Calling setConsent('denied') stops collection and clears the event queue, but fields already passed to the methods may remain in page memory and be included in the next settings request. The order of calls is described in the consent article.
To select content, the settings request may include URL query parameter values and cookies accessible to JavaScript. The widget limits their size and skips fields with clearly sensitive names, but a field name is not reliable protection. Do not put secrets or personal data in URLs or cookies accessible to JavaScript unless you are prepared to send them to Flowtomate. The event request works differently: it contains query parameter names without their values, and no cookie values. See the events article for details about track.
On sign-out, run await window.FlowtomateWidget.reset() before another user signs in. If consent belongs to the account, use await reset({ clearConsent: true }) and request it again. Do not pass passwords, tokens, card details, or other secrets through identify, setTraits, or track.
If external response delivery is enabled, your receiver may receive email, response text, and the external user ID. The delivery request is unsigned. Validate incoming data, restrict access to the endpoint, and do not write responses to a shared log.