Embed

Sign your customer in

The Prio window signs your customer in with the tokens your page already holds from POST /users or GET /users/:id. The script posts them to the window once it is ready, and the window accepts them only from a site on your allowed list.

Allowed sites

List every origin that shows a Prio button — scheme and host, such as https://app.clearpath.example — on the Keys tab of your console. Prio can be framed only by those sites; any other site gets an error event instead of a window. If the script sits inside your own frame, every origin in that chain must be listed.

What is posted

Message Carries Direction
prio-embed-ready nothing Prio → your page
prio-embed-init jwt, refreshJwt your page → Prio
postMessage
// the script does this for you; shown so you know what leaves your page
frame.contentWindow.postMessage(
  { type: "prio-embed-init", jwt, refreshJwt },
  "https://heyprio.com"
);

The session lives only in the window’s memory: Prio writes nothing to your customer’s browser storage, and closing the window ends it.

Your page’s Content-Security-Policy

Directive Must allow
script-src https://heyprio.com
frame-src https://heyprio.com
style-src https://use.typekit.net and inline style
font-src https://heyprio.com and https://use.typekit.net

Prio may display inaccurate info at times, please double check the responses.