> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vocily.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# The website widget

> The embeddable chat and voice widget on an agent.

Every agent has exactly one widget, prepared for you on first read — so this never 404s and there
is nothing to create. There is nothing to delete either: you configure the one it has.

<Note>
  **Singular, with no id in the path.** This used to be a list at `/widgets` plus a read at
  `/widgets/{widget_id}`. Since an agent only ever has one, the id was a value you had to fetch
  before you could use any of the other routes, and could only ever be that one value. It is
  still on the body — useful in logs, and for telling one rotation from another.
</Note>

The public key is what your website embeds, and it is shown **once**, when the key is
[rotated](/developers/widgets/rotate-key) — never on a read. `public_key_prefix` is the
safe-to-log half, for identifying which key a page is currently using.

`allowed_origins` is the security boundary: the widget only runs on the sites you list.


## OpenAPI

````yaml developers/openapi.json GET /v1/agents/{agent_id}/widget
openapi: 3.1.0
info:
  title: Vocily API
  description: >-
    Public REST API for Vocily. Build and configure an agent, publish a version
    and put it live, place outbound calls, and read back calls, chats and what
    the agent remembered. Authenticate with a workspace API key as a Bearer
    token.


    Some things stay in the dashboard, by design: creating an API key, buying or
    connecting a phone number, setting an agent's webhook URL, connecting
    WhatsApp and its templates, building HTTP tools, and running batch
    campaigns.
  version: v1
servers:
  - url: https://api.vocily.ai
    description: Production
security: []
paths:
  /v1/agents/{agent_id}/widget:
    get:
      tags:
        - widgets
      summary: Get Agent Widget
      description: >-
        The agent's widget.


        An agent holds exactly one, prepared on first read — so this never 404s
        and never comes back

        empty. It carries `public_key_prefix`, not the key: the secret is shown
        once, at rotation.
      operationId: get_agent_widget_v1_agents__agent_id__widget_get
      parameters:
        - name: agent_id
          in: path
          required: true
          schema:
            type: string
            title: Agent Id
          description: The agent's id, as `GET /v1/agents` returns it.
      responses:
        '200':
          description: >-
            The agent's widget. One is prepared on first read, so this never
            404s.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  agent_id:
                    type: string
                  name:
                    type: string
                  allowed_origins:
                    items:
                      type: string
                    type: array
                  enabled_modes:
                    type: object
                    properties:
                      chat:
                        type: boolean
                      talk:
                        type: boolean
                  theme:
                    type: object
                  default_variables:
                    type: object
                  public_key_prefix:
                    type: string
                  status:
                    type: string
                  created_at:
                    type: string
                    format: date-time
                  updated_at:
                    type: string
                    format: date-time
              example:
                name: Website widget
                allowed_origins: []
                enabled_modes:
                  chat: true
                  talk: false
                theme:
                  title: Acme Support
                  subtitle: Ask anything or start a web call
                  welcome_message: Hi! How can I help you today?
                  logo_url: null
                  accent_color: '#7C83FF'
                  launcher_text_color: '#FFFFFF'
                  user_message_color: '#7C83FF'
                  user_message_text_color: '#FFFFFF'
                  assistant_message_color: '#17171D'
                  assistant_message_text_color: '#E5E7EB'
                  position: bottom-right
                  launcher_label: Chat
                  button_shape: rounded
                  panel_radius: 24
                  message_radius: 16
                  launcher_radius: 999
                  icon_radius: 999
                  dock_icon_size: 26
                  launcher_padding_x: 18
                  launcher_padding_y: 13
                  widget_width: 380
                  widget_height: 620
                  show_inbound_number: true
                default_variables: {}
                id: 00000011-0000-4000-8000-000000000011
                agent_id: 00000005-0000-4000-8000-000000000005
                public_key_prefix: pk_widget_live_EXA
                status: active
                created_at: '2026-09-16T19:38:04.301686Z'
                updated_at: '2026-09-16T19:38:04.301686Z'
        '401':
          description: Missing or invalid API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
              example:
                detail: Invalid API key
                code: UNAUTHORIZED
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
        '429':
          description: Rate limit exceeded — honor `Retry-After`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
              example:
                code: rate_limited
      security:
        - bearerAuth: []
components:
  schemas:
    ApiError:
      type: object
      description: >-
        Error envelope. `code` is derived from the HTTP status, so branch on it
        for the CLASS of failure; the specific reason is `detail.code`. Every
        public refusal carries both.
      properties:
        detail:
          type: object
          description: >-
            The reason. `code` is the domain reason (e.g. `call_not_found`) and
            `message` is a sentence safe to log. On a `422` it also carries
            `errors[]`, one entry per rejected field — see
            `HTTPValidationError`.
          properties:
            code:
              type: string
              example: call_not_found
            message:
              type: string
              example: Call not found
          required:
            - code
            - message
        code:
          type: string
          description: Derived from the HTTP status, not the domain reason.
          example: NOT_FOUND
    HTTPValidationError:
      type: object
      title: HTTPValidationError
      description: >-
        A request the API could not read: a field of the wrong type, out of
        range, missing, or one we do not accept. Same envelope as every other
        error.
      properties:
        detail:
          type: object
          description: >-
            What was wrong, as `code`, a one-line `message`, and every offending
            field in `errors`.
          required:
            - code
            - message
            - errors
          properties:
            code:
              type: string
              enum:
                - validation_error
            message:
              type: string
              description: >-
                The first problem in one line, with a count of the rest — e.g.
                `model.temperature: Input should be less than or equal to 2 (and
                1 more)`.
            errors:
              type: array
              items:
                $ref: '#/components/schemas/ValidationError'
              description: >-
                One entry per offending field. **Every problem is reported at
                once**, not just the first, so a malformed body needs one round
                trip to fix rather than one per field.
        code:
          type: string
          enum:
            - VALIDATION_ERROR
          description: Derived from the HTTP status, as on every error.
    ValidationError:
      type: object
      title: ValidationError
      required:
        - field
        - message
        - type
      properties:
        field:
          type: string
          description: >-
            The offending field as a path from the root of your request —
            `voice.speed`, `variables[0].key`, or `query.limit` for a query
            parameter. **This is the field to read.**
        message:
          type: string
          description: What is wrong with it, in plain language.
        type:
          type: string
          description: >-
            A stable machine code for the kind of failure, e.g.
            `extra_forbidden` for a field we do not accept, `missing` for a
            required one, or `less_than_equal` for a number out of range. Switch
            on this rather than on `message`, which may be reworded.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Your API key as a Bearer token, e.g. `Authorization: Bearer vk_…`.'

````