Sign your customer in
The Prio window signs your customer in with the tokens your page already holds from POST /users or GET /users/:id. The script posts them to the window once it is ready, and the window accepts them only from a site on your allowed list.
Allowed sites
List every origin that shows a Prio button — scheme and host, such as https://app.clearpath.example — on the Keys tab of your console. Prio can be framed only by those sites; any other site gets an error event instead of a window. If the script sits inside your own frame, every origin in that chain must be listed.
What is posted
| Message | Carries | Direction |
|---|---|---|
| prio-embed-ready | nothing | Prio → your page |
| prio-embed-init | jwt, refreshJwt | your page → Prio |
The session lives only in the window’s memory: Prio writes nothing to your customer’s browser storage, and closing the window ends it.
Your page’s Content-Security-Policy
| Directive | Must allow |
|---|---|
| script-src | https://heyprio.com |
| frame-src | https://heyprio.com |
| style-src | https://use.typekit.net and inline style |
| font-src | https://heyprio.com and https://use.typekit.net |