Every block is either a drop-in widget your page loads with one script tag, or an API your server calls. Widgets never see your API key.
How widgets authenticate
- Your server trades its API key for a short-lived site token with
POST https://api-v2.dropcowboy.com/phone/public/embed/token. The token lasts one hour at most and carries only the scopes you ask for. - Your page loads the widget script and calls
init({ token }). Mint a new token when it expires. - The token goes in
init(), never in a URL, and the API key never reaches the browser.
See Embed site tokens for scopes and the full request.
Rules for integrators and AI agents
- Do not rebuild WebRTC calling or the inbox. Use the Dock, Dialer, and Shared Inbox.
- Do not configure SIP, STUN, or TURN servers in your page. The calling widgets get that from the site token.
- Detection runs on your server over a WebSocket with a Detection API key. The browser is never part of it.
- Headless work (sending, contacts, campaigns) goes to the REST API or MCP.
- To add your own panel inside the Drop Cowboy® dashboard rather than embed Drop Cowboy in your app, use a Canvas widget: your server answers a signed request with Canvas JSON.