Appearance
Pinned version and SRI
/widget.js always serves the server's current loader. If your security policy wants a fixed file checked by the browser, load the pinned copy with Subresource Integrity instead:
html
<script src="https://chat.example.com/widget@0.1.0.js"
integrity="sha384-..."
crossorigin="anonymous"
data-bot="pk_your_bot_id" async></script>crossorigin="anonymous" is required for SRI on a script from another origin (the server sends Access-Control-Allow-Origin: * for it). The pinned file is cached for a year; /widget.js for five minutes.
Where to find the version and hash
- The bot's embed code in the admin panel shows the pinned tag, with the current version and hash.
GET https://chat.example.com/manifest.jsonlists them:
json
{
"version": "0.1.0",
"loader": {
"file": "widget.js",
"pinned": "widget@0.1.0.js",
"integrity": "sha384-...",
"bytes": 32395,
"gzip": 11187
},
"frame": { "entry": "assets/index-....js", "css": "assets/index-....css", "gzip": 39051 },
"builtAt": "2026-10-07T21:24:34.449Z"
}- The REST API's
GET /api/v1/bots/{id}/embedreturnswidgetVersion,pinnedUrlandsrialong with the bot's public id and host.
With the npm package, pass version and integrity to bootWirefaceChat() or loadWirefaceChat().
What pinning does and doesn't fix
Only the loader (widget.js) is pinned. The chat window, the face engine and the protocol come from your server, at its current version, as they must to talk to it.
Every released loader is kept (in packages/widget/releases/ in the repo, and in the Docker image), so a page pinned to an older version keeps loading after you upgrade the server. Update the pinned version when you want the newer loader's features.
A released version never changes: its file and SRI hash stay the same for good. (Building a changed loader without bumping the widget's version fails in CI, or with RELEASE=1.) Servers that keep the releases somewhere else point WIDGET_RELEASES at that folder.