Going live
Before the chat or the form goes on a real website.
One publishable key per site
List only its production origins, www included if visitors use it. No staging or localhost entries.
Secret keys stay on the server
Environment variables, never a page or a public repository. Leaked: revoke under Development > API Keys and create another.
Handle four errors
400: a field failed validation, usually more than 50 messages. Trim client-side.401: key revoked or mistyped. Show "unavailable", check the key.403: wrong key kind, or origin not allowed. Add the origin to the key.429: too many requests. Disable Send for a minute.
Point at the right environment
This one is https://staging.api.naalyaschools.ac.ug. Keys are per environment; a staging key does not work in production.
Where it lands
- Enquiries: Enquiries in the school's Hub, under the reference you showed. The school can also post each one to a Microsoft Teams channel.
- Chats: not stored. Name and intro come from School Settings > AI assistant; knowledge comes from documents the school marks public.