One script tag. Here is exactly what it reads and sends.
Third-party scripts run with your page’s access, so you should know what this one does before you add it.
Install
index.html
<script src="https://api.useskate.com/skate.js" data-site="your-site-id" async></script>
Remove the tag to switch it off.
What it sends
- The request, plus the visible controls and text of the current screen.
- The path and status of same-origin requests, so it can tell whether an action worked.
What it never sends
- Password, card and one-time-code fields.
- Cookies, request headers and request bodies.
- Anything inside an element you mark
data-private.
How it acts
In the browser, as the signed-in user, through your own UI. It has no API keys to your backend. Model keys stay on our server.
More
Docs and the security page.