Browse the Help Centre

Widget script reference

The tag

<script src="https://api.usekaras.com/widget/v1.js"
        data-key="wk_live_yourcompany" async></script>

Attributes

data-key (required). Your widget key. Public by design — see Your widget key and domain allowlist.

data-user-name, data-user-email (optional). If your page already knows who the visitor is, pass them through and the handoff form arrives pre-filled so the visitor only confirms.

These are not authentication. An attribute in a page is as editable as the form it replaces, so a ticket can claim to be from someone it is not. The ticket records that the identity came from the page rather than a form and never marks it verified. If you need it to be trustworthy, ask us about signed identity.

What the script loads

The bundle is about 22 kB compressed and ships without a source map. On start it fetches your configuration from /v1/widget/config, which is cached, so a returning visitor's widget appears without waiting on it.

Nothing is loaded from a third-party host. There are no analytics or tracking requests.

Isolation from your page

The widget renders inside a closed shadow root. Your stylesheets cannot reach into it and its styles cannot escape onto your page, so it can be dropped onto any site without a collision. The trade is that appearance is configured on your account rather than with CSS — see Branding the widget.

Because the root is closed, your page's JavaScript cannot inspect or drive the widget's internals either.

Content Security Policy

If your site sets a CSP, allow api.usekaras.com as both a script source and a connect source. The widget creates its styles inside its own shadow root; if your policy restricts inline styles, tell us and we will confirm what your policy needs.

Browser support

Current versions of Chrome, Edge, Firefox and Safari, on desktop and mobile. The widget requires shadow DOM support, which every supported browser has had for years.

Accessibility

The widget is keyboard operable throughout, labels its controls for screen readers, respects a visitor's reduced-motion preference, and is tested against automated accessibility checks on a deliberately hostile host page. If you have a specific conformance requirement, ask and we will tell you where we stand against it rather than claiming a level.

Removing it

Delete the tag. There is nothing left behind on your site: no cookies on your domain, no global variables you need to clean up, no stored data outside the visitor's own browser.