Guide menu

Widget

How is widget access protected, and how does a customer resume?

The allowed domain protects where the widget can open, while a per-request token protects the customer's individual workspace.

The client key identifies the widget and is public. The end-user token identifies one request and must be treated as a private access link. These two keys have different jobs and should not be exchanged.

Returning on the same or a new device

On the same browser, Pen's Work can restore the workspace from locally saved access information. On a new device, the current fallback uses the phone information entered with the request; it is a convenience recovery path, not SMS one-time-password verification.

Operational precautions

Register only domains you control, send workspace links to the intended customer, and close access when the work should no longer be visible. For highly sensitive matters, confirm the recipient through a separate channel before sending the link.