
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@pointerdevks/pointerai-widget
Advanced tools
Embeddable PointerAI chat widget for script-tag/CDN integration.
This package now ships a real source/build pipeline and uses @pointerdevks/pointerai-client under the hood.
<script src="https://cdn.jsdelivr.net/npm/@pointerdevks/pointerai-widget@latest/dist/pointerai-widget.js" defer></script>
cd packages/pointerai-widget
npm install
npm run lint
npm run build
npm run smoke
<script>
window.pointeraiWidgetConfig = {
apiBaseUrl: 'https://api.example.com',
projectId: '<PROJECT_ID>',
publishableKey: '<PUBLISHABLE_KEY>',
title: 'Support chat',
launcherLabel: 'Chat with us',
};
</script>
<script src="https://cdn.jsdelivr.net/npm/@pointerdevks/pointerai-widget@latest/dist/pointerai-widget.js" defer></script>
Provide endUserToken from your backend so the widget can exchange it for a short-lived runtime session token:
<script>
window.pointeraiWidgetConfig = {
apiBaseUrl: 'https://api.example.com',
projectId: '<PROJECT_ID>',
publishableKey: '<PUBLISHABLE_KEY>',
endUserToken: '<END_USER_JWT>',
};
</script>
<script src="https://cdn.jsdelivr.net/npm/@pointerdevks/pointerai-widget@latest/dist/pointerai-widget.js" defer></script>
apiBaseUrl (required)projectId (required)publishableKey (required)endUserToken (required for login_required projects)getEndUserToken (optional async token provider for login_required projects)anonUidmetadatatitlesubtitlelauncherLabellauncherIconlauncherIconUrllogoUrlwelcomeMessageplaceholdersendLabelthemeColorpanelBackgroundColormessagesBackgroundColortextColormutedTextColorpanelBorderColorassistantBubbleColorassistantTextColoruserBubbleColoruserTextColorfontFamilyborderRadiuszIndexposition (right / left)sideOffsetbottomOffsetwidthmaxHeightopenOnLoadhistoryFetchLimit (default 100, max 200)<script>
(async function () {
await window.PointerAIWidget.init({
apiBaseUrl: 'https://api.example.com',
projectId: '<PROJECT_ID>',
publishableKey: '<PUBLISHABLE_KEY>',
});
})();
</script>
<script>
window.PointerAIWidget.open();
window.PointerAIWidget.close();
await window.PointerAIWidget.sendMessage('Hello from host page');
await window.PointerAIWidget.setEndUserToken('<FRESH_END_USER_JWT>');
await window.PointerAIWidget.reconnect();
</script>
anonUid in localStoragesessionUidendUserToken via /api/runtime/sessionslocalStorage per projectlistMessages and replaces local cache with server truthFAQs
Embeddable PointerAI chat widget for script-tag/CDN integrations.
The npm package @pointerdevks/pointerai-widget receives a total of 0 weekly downloads. As such, @pointerdevks/pointerai-widget popularity was classified as not popular.
We found that @pointerdevks/pointerai-widget demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.