@quarterzip.ai/sdk
v1.0.0
Published
Quarterzip embeddable conversational agent SDK.
Readme
@quarterzip.ai/sdk
A thin, dependency-free loader for the Quarterzip embeddable voice-agent SDK.
It is responsible for managing the lifecycle of a sandboxed, cross-origin iframe that loads the live SDK from Quarterzip's servers, mirroring the call controls into a floating Picture-in-Picture window, and brokering a private message channel between the two. Everything Quarterzip serves runs inside that sandbox and cannot touch your page's DOM, cookies or storage.
The latest documentation is available at docs.quarterzip.ai
Install
pnpm add @quarterzip.ai/sdkCSP requirements
If your page sends a Content Security Policy, it must allow Quarterzip's origin to be framed or the iframe never loads:
Content-Security-Policy:
frame-src https://sdk.quarterzip.ai;
child-src https://sdk.quarterzip.ai;Permissions Policy
Only relevant if your page already sends a Permissions-Policy header — if it sends none, the
allow attribute this package sets on the iframe is sufficient and there is nothing to do. If it
does send one, it must grant these features to Quarterzip's origin or delegation fails:
Permissions-Policy:
microphone=(self "https://sdk.quarterzip.ai"),
display-capture=(self "https://sdk.quarterzip.ai"),
autoplay=(self "https://sdk.quarterzip.ai"),
speaker-selection=(self "https://sdk.quarterzip.ai"),
storage-access=(self "https://sdk.quarterzip.ai")Delegation is an intersection: the iframe only receives a capability your top-level page already has, so listing a feature here grants nothing if your own page is denied it.
Usage
import { Quarterzip } from '@quarterzip.ai/sdk';
button.addEventListener('click', () => {
Quarterzip.open({
agentId: 'agt_123',
workspaceToken: 'wt_public_abc', // public, not a secret
user: {
id: 'your-user-id', // required; may be opaque or hashed
email: '[email protected]', // optional
displayName: 'Jane Doe' // optional
},
context: 'Optional free text passed to the agent',
onEnd: ({ reason }) => analytics.track('call_ended', { reason }),
onError: ({ code, fatal }) => console.warn('Quarterzip call failed', code, fatal)
});
});
// later
Quarterzip.close();Licence
MIT — see LICENSE.
This covers this package: the client-side loader that stands up the sandboxed iframe. The Quarterzip service the frame connects to, and the bundle it serves at runtime, are not covered by it and are not open source.
