OttobotEmbed_createEmbedToken
POST/api/ottobot/embed-token
Exchange an organization API key for a short-lived OttoBot chat bearer.
Call this from your BACKEND — the API key must never reach a browser. Pass
the returned token to your page and postMessage it into the embedded
OttoBot iframe.
Authenticate with either x-api-key: <key> or
Authorization: Bearer <key>.
organizationSlug must match the organization the presented key belongs
to; a mismatch returns 403 and mints nothing. The returned token carries
exactly the ottobot:chat scope and expires in about five minutes — both
are fixed server-side and cannot be widened by the caller.
Pass endUserEmail to attribute the session to one of your end users. That
address must already be an HG Insights user with membership in
organizationSlug; if it is not, the call returns 403 end_user_not_eligible
and mints nothing. "Not an HG Insights user" and "not a member of this
organization" return an identical response by design, so this endpoint
cannot be used to discover which addresses have HG Insights accounts.
Request
Responses
- 200
- default
The request has succeeded.
An unexpected error response.