Embed the editor

Let your customers create, edit, test and deploy their decisions inside your app — embed sessions from your backend, the @dcision/embed script, permissions and events.

Your end users get Dcision's decision screens inside your app: the decisions list, templates, Create with the agent, the editor and visual builder, the playground, deploy and the executions of each decision. They act in their sub-workspace only, and never see API keys, billing or settings.

1. Open a session (your backend)

When a signed-in user opens the page, your backend calls POST /v1/embed/sessions with your API key — never from the browser:

// POST /api/dcision/session in your backend — the user and their workspace come from YOUR session, never the request.
const session = await dcision.embed.createSession({
  workspace: { external_id: currentWorkspace.id, name: currentWorkspace.name },
  user: { id: currentUser.id, name: currentUser.name },
  permissions: canEdit ? undefined : ["decisions:read", "executions:read"],
  start_path: body.path, // where the user was (sent back by the embed after a session expires)
  locale: "pt",
});
return { url: session.url };

url is a one-time launch link valid for 60 seconds. The session itself lasts ttl_seconds (default 1 hour, up to 12).

2. Mount it (your page)

import { mount } from "@dcision/embed";

const embed = await mount(document.getElementById("decisions")!, {
  getSession: ({ path }) => fetch("/api/dcision/session", { method: "POST", body: JSON.stringify({ path }) }).then((r) => r.json()),
  onEvent: (event) => {
    if (event.type === "decision.deployed") refreshStrategies();
  },
});
  • The iframe grows with its content (height: "auto") and reopens a session by itself when one expires, on the page the user was on.
  • embed.navigate("/decisions/new") opens a page; embed.setTheme("dark") switches the theme.
  • Allow the frame in your Content-Security-Policy: frame-src https://app.dcision.io.
  • Until @dcision/embed is on npm, copy its source from the Dcision repository (packages/embed): it has no dependencies.

Permissions

PermissionLets the user
decisions:readSee decisions, versions, the overview and the agent conversation
decisions:writeCreate (from templates), edit, duplicate and test in the playground
decisions:deployDeploy, disable and enable
decisions:deleteDelete decisions
executions:readSee executions and destination deliveries
agentCreate and edit with the agent

Default: all of them. Map them from your own roles — e.g. viewers get decisions:read and executions:read.

Events

The embed posts these messages to your page (only to your allowed origins). They carry ids, slugs, versions and paths — never tokens or inputs.

EventWhen
ready, navigateThe embed loaded, or the user moved to another page (path)
resizeThe content height changed (height)
decision.created · decision.updated · decision.deletedA decision was created, its draft saved, or deleted
decision.deployed · decision.enabled · decision.disabledWhat production runs changed (version)
session.expiring · session.expiredThe session ends in 2 minutes / ended (the script reopens it)

Security

  • Only the origins allowed in Settings → Partner can frame the editor, and only for the session's lifetime. Opened outside an iframe, the link shows nothing.
  • Your API key stays on your server. Revoke a session with DELETE /v1/embed/sessions/{id}, or all of a user's with POST /v1/embed/sessions/revoke; revoking or regenerating the API key that created them closes them too.
  • The user you send is shown in the editor and the agent chat and counts for the agent's per-person limits. Take it from your own session.

On this page