Embed the editor
Let your customers create, edit, test and deploy their decisions inside your app — embed sessions from your backend, the @dcision/embed script, permissions and events.
Your end users get Dcision's decision screens inside your app: the decisions list, templates, Create with the agent, the editor and visual builder, the playground, deploy and the executions of each decision. They act in their sub-workspace only, and never see API keys, billing or settings.
1. Open a session (your backend)
When a signed-in user opens the page, your backend calls POST /v1/embed/sessions with your API key — never from the browser:
// POST /api/dcision/session in your backend — the user and their workspace come from YOUR session, never the request.
const session = await dcision.embed.createSession({
workspace: { external_id: currentWorkspace.id, name: currentWorkspace.name },
user: { id: currentUser.id, name: currentUser.name },
permissions: canEdit ? undefined : ["decisions:read", "executions:read"],
start_path: body.path, // where the user was (sent back by the embed after a session expires)
locale: "pt",
});
return { url: session.url };url is a one-time launch link valid for 60 seconds. The session itself lasts ttl_seconds (default 1 hour, up to 12).
2. Mount it (your page)
import { mount } from "@dcision/embed";
const embed = await mount(document.getElementById("decisions")!, {
getSession: ({ path }) => fetch("/api/dcision/session", { method: "POST", body: JSON.stringify({ path }) }).then((r) => r.json()),
onEvent: (event) => {
if (event.type === "decision.deployed") refreshStrategies();
},
});- The iframe grows with its content (
height: "auto") and reopens a session by itself when one expires, on the page the user was on. embed.navigate("/decisions/new")opens a page;embed.setTheme("dark")switches the theme.- Allow the frame in your Content-Security-Policy:
frame-src https://app.dcision.io. - Until
@dcision/embedis on npm, copy its source from the Dcision repository (packages/embed): it has no dependencies.
Permissions
| Permission | Lets the user |
|---|---|
decisions:read | See decisions, versions, the overview and the agent conversation |
decisions:write | Create (from templates), edit, duplicate and test in the playground |
decisions:deploy | Deploy, disable and enable |
decisions:delete | Delete decisions |
executions:read | See executions and destination deliveries |
agent | Create and edit with the agent |
Default: all of them. Map them from your own roles — e.g. viewers get decisions:read and executions:read.
Events
The embed posts these messages to your page (only to your allowed origins). They carry ids, slugs, versions and paths — never tokens or inputs.
| Event | When |
|---|---|
ready, navigate | The embed loaded, or the user moved to another page (path) |
resize | The content height changed (height) |
decision.created · decision.updated · decision.deleted | A decision was created, its draft saved, or deleted |
decision.deployed · decision.enabled · decision.disabled | What production runs changed (version) |
session.expiring · session.expired | The session ends in 2 minutes / ended (the script reopens it) |
Security
- Only the origins allowed in Settings → Partner can frame the editor, and only for the session's lifetime. Opened outside an iframe, the link shows nothing.
- Your API key stays on your server. Revoke a session with
DELETE /v1/embed/sessions/{id}, or all of a user's withPOST /v1/embed/sessions/revoke; revoking or regenerating the API key that created them closes them too. - The
useryou send is shown in the editor and the agent chat and counts for the agent's per-person limits. Take it from your own session.
Sub-workspaces
One sub-workspace per customer of your app, by your own id — create it, copy your decisions into it, run them with Dcision-Workspace, limit and watch its usage.
Use Dcision in Claude Code
Connect Claude Code to Dcision with the MCP server and the Dcision skill — list, check and run decisions, write and validate decision schemas, and use the CLI and SDKs from your agent.