Skip to content

Security ​

The public key is public ​

The key that starts with pk_ is like a publishable key. It is safe in page source. It identifies your workspace and only grants access to content you have published. It does not need to change when you add or edit content. Rotate it from Settings → Developers only if you want to retire an embed.

Protect identities ​

Anyone with your public key can call identify with any user id. Turn on identity verification and sign user ids on your server. Never put the identity secret in client code.

Allowed origins ​

The allow-list restricts which browsers can use your key. It is not authentication.

Content Security Policy ​

If your site sends a Content-Security-Policy header, allow:

DirectiveValue
script-srchttps://app.justonecx.qd.je (script tag install only)
connect-srchttps://api.justonecx.qd.je and wss://api.justonecx.qd.je (chat)
style-src'unsafe-inline', because the SDK injects one <style> element

What the SDK stores ​

  • A random visitor id in localStorage.
  • Small per-visitor flags, for example which content was dismissed.

It sets no cookies. reset() clears the visitor id.

Only http and https links are rendered in announcements and other content.

Report a vulnerability ​

Contact the JustOneCX team privately through your dashboard account. Do not post details publicly.

JustOneCX