← Back to help centre

Public widgets

Understanding WebCheck widget privacy

Know what a public widget shares, what it keeps private and how to revoke an exposed embed token.

A WebCheck widget is public by design. Its embed code contains a public lookup token, and anyone who can read the embed can request the widget’s status feed. Do not treat the token as a password or put confidential information in public names or labels.

What the public widget shares

The widget feed includes the site name and status, plus uptime or current availability. Average response time and the last-checked time are optional display fields controlled by the widget settings. The embed shows the site name, status label and any enabled metrics.

The widget does not publish monitored URLs, check configuration, internal record IDs or detailed check evidence. A status page is different: it can intentionally publish selected component names, public notes, recent status history and incident history.

Review names before embedding

Choose a site name and widget labels that are appropriate for visitors. Do not use internal hostnames, customer identifiers or operational details that you would not publish on your own website.

Revoke an exposed widget

The embed token is visible in the script placed on your site. If you no longer want that widget feed to be available, revoke its token in Widget administration. The existing embed will stop working; create and share a new widget only with the intended audience.