# Embedded usage insights

Put spend and savings trends, usage by model and request counts in the dashboards your team already uses. Viewers need no new logins.

## Create a token and embed the page

1. As an organization admin or personal account owner, open Embed / Share on your existing insights dashboard.

2. Choose the whole account or organization, or one API key. Add exact HTTPS origins such as https://portal.example.com; the maximum number N is controlled by a setting.

3. Choose an expiry within the maximum duration set by the platform setting, or choose no expiry if the platform allows it, then create the token.

4. Save the blemb_ token, embed URL and iframe snippet shown once. Paste the snippet into a page on an allowed domain.

## The iframe example

Replace <token> with your embed token. The URL is https://bazaarlink.ai/embed/insights/<token>. Keep it private.

```html
<iframe src="https://bazaarlink.ai/embed/insights/<token>" width="100%" height="720" style="border:0"></iframe>
```

## Allowed domains and CSP

Use exact https origins (scheme, hostname and port), not a page path or wildcard. CSP frame-ancestors permits framing only on the token’s allowed domains. If https://portal.example.com is allowed but https://other.example.com is not, the browser blocks the iframe on the latter.

## Expiry and revocation

The token is stored hashed. You can revoke it at any time; the URL stops working immediately. An expired token no longer grants access. Revoke tokens when staff leave.

## Rate limits

Requests are rate-limited per token, with a default of 60 requests per minute. This is a configurable limit, not an unlimited data feed.

## Refresh and freshness

Data comes from hourly usage rollups. The page refreshes about every 5 minutes, so figures can lag real time by up to about an hour plus the refresh interval. Check the displayed “as of” time.

## What viewers can see

Viewers see customer-priced spend, savings trends, model names and request counts for the selected scope. Anyone with the URL can view it from an allowed domain: treat the URL like a password.

## Read-only access

An embed token cannot call any model or API endpoint. It only reads the embedded insights surface and its data endpoint. The page uses no-store and no-referrer.

## Advanced data access

GET https://bazaarlink.ai/api/embed/insights

GET the URL below with the Authorization header using the “Bearer” scheme and <embed token>. Read-only, may change; the iframe is the supported v1 surface.

## Frequently asked questions

### Do viewers need a new login?

No. The URL provides read-only viewing from an allowed domain; share it only with intended viewers.

### Is this a real-time monitor?

No. Hourly rollups and the approximately 5-minute refresh mean data may be delayed. Use the “as of” time.

### Can I recover a token I did not save?

The raw token is shown once and stored hashed. Revoke that token and create a new one.
