Appearance
Security
The public key is public
The key that starts with pk_ is like a publishable key. It is safe in page source. It identifies your workspace and only grants access to content you have published. It does not need to change when you add or edit content. Rotate it from Settings → Developers only if you want to retire an embed.
Protect identities
Anyone with your public key can call identify with any user id. Turn on identity verification and sign user ids on your server. Never put the identity secret in client code.
Allowed origins
The allow-list restricts which browsers can use your key. It is not authentication.
Content Security Policy
If your site sends a Content-Security-Policy header, allow:
| Directive | Value |
|---|---|
script-src | https://app.justonecx.qd.je (script tag install only) |
connect-src | https://api.justonecx.qd.je and wss://api.justonecx.qd.je (chat) |
style-src | 'unsafe-inline', because the SDK injects one <style> element |
What the SDK stores
- A random visitor id in
localStorage. - Small per-visitor flags, for example which content was dismissed.
It sets no cookies. reset() clears the visitor id.
Links in content
Only http and https links are rendered in announcements and other content.
Report a vulnerability
Contact the JustOneCX team privately through your dashboard account. Do not post details publicly.