Account & API keys

Your GuidMe account lets you manage apps, documents, billing, referral access, and API keys.

Account settings

From the dashboard or user menu you can:

  • Update your profile details (name, email, avatar)
  • Manage notification preferences
  • View and manage your subscription (see Billing)
  • Open the referral program from Profile or Organization > Subscription

API keys

API keys belong to the organization and have scopes. The Connection page creates a publishable widget key (starts with gm_live_). Pair it with the app ID in every embed:

<script
  src="https://widget.guidme.ai/v1/loader.js"
  data-key="gm_live_xxxxxxxxxxxx"
  data-app-id="11111111-1111-4111-8111-111111111111"
></script>
  • Widget keys are publishable and visible in browser source. App-level allowed origins restrict where each embed can run.
  • Admin-scoped keys and platform credentials are secrets. Never put them in browser code.

Security

  • Keep admin-scoped and other server-side credentials private. Do not commit them to public repositories or share them in screenshots.
  • Use allowed origins in the app settings so the widget works only on your domains.
  • Regenerate the widget key from Connection when you need to rotate it, then update every embed that uses it.

Backend API

Server-side integrations use an API key with the scope required by the endpoint. Never reuse an admin-scoped key in browser code. See the deployed Swagger documentation for endpoint-specific authentication requirements.