← Optiview

Enterprise Integration Snippets

Verify ownership, generate a domain-scoped Enterprise API key, and publish your approved context before connecting your server. These examples require adaptation and testing against your own routing and security policies.

Security & Compliance Standards

Shared request handler

Include this helper alongside either adapter below. Replace the hostname and public-path allowlist. Do not forward credentials, session cookies or API keys to the origin. Outbound Optiview fetches carry a loop marker; the helper serves the origin for those requests.

// Server-side only. Store the key in an environment secret.
async function optimized(request, key, fallback) {
  const url = new URL(request.url);
  // Scope to a public-page allowlist for your own site.
  if (url.hostname !== 'www.your-domain.com' ||
      !['/', '/product/'].includes(url.pathname) || url.search ||
      request.method !== 'GET' || request.headers.has('Cookie') ||
      request.headers.has('Authorization') ||
      request.headers.has('X-Optiview-Fetch')) return fallback();
  let md = 0, html = 0;
  for (const part of (request.headers.get('Accept') || '').toLowerCase().split(',')) {
    const [type, ...params] = part.trim().split(';');
    const quality = params.find(p => p.trim().startsWith('q='));
    const q = quality ? Number(quality.trim().slice(2)) : 1;
    if (!Number.isFinite(q) || q < 0 || q > 1) continue;
    if (type === 'text/markdown') md = q;
    if (type === 'text/html') html = q;
  }
  if (!key || !md || md < html) return fallback();
  try {
    const r = await fetch('https://app.optiview.ai/api/v1/render', {
      method: 'POST',
      headers: {Authorization: 'Bearer ' + key, 'Content-Type': 'application/json'},
      body: JSON.stringify({url: url.href}),
      signal: AbortSignal.timeout(12000)
    });
    if (!r.ok) return fallback();
    const data = await r.json();
    if (!data.success || typeof data.payload !== 'string' ||
        data.content_type !== 'text/markdown') return fallback();
    return new Response(data.payload, {headers: {
      'Content-Type': 'text/markdown; charset=utf-8',
      'Vary': 'Accept', 'Cache-Control': 'no-store'
    }});
  } catch { return fallback(); }
}

Vercel / Next.js

Use a server deployment that supports middleware. Newer Next.js versions may use the proxy convention; static exports cannot run this code. Keep the key server-side, without a NEXT_PUBLIC prefix.

import {NextResponse} from 'next/server';
// Include optimized() above.
export function middleware(request) {
  return optimized(request, process.env.OPTIVIEW_API_KEY,
    async () => NextResponse.next());
}
export const config = {matcher: ['/', '/product/']};

Cloudflare Workers

// Include optimized() above.
export default {
  fetch(request, env) {
    return optimized(request, env.OPTIVIEW_API_KEY,
      () => fetch(request));
  }
};

Cloudflare Pages — our own deployment

Optiview’s marketing site is a static Next.js export on Pages. Its Pages Function wraps the asset response with the same negotiation, loop bypass and fail-open pattern:

// functions/_middleware.ts; include optimized() above.
export const onRequest = ({request, env, next}) =>
  optimized(request, env.OPTIVIEW_API_KEY, next);

Standard cURL

curl https://app.optiview.ai/api/v1/render \
  -H "Authorization: Bearer $OPTIVIEW_API_KEY" \
  -H 'Content-Type: application/json' \
  --data '{"url":"https://www.your-domain.com/product/"}'

Security and deployment

Delivery follows explicit content negotiation. We do not require User-Agent spoofing, and API keys are strictly domain-scoped. A crawler name alone does not trigger delivery. Keep keys out of browser code and source control; honor failed API responses by serving the origin.

Shopify theme code cannot securely hold this key or intercept HTTP responses. Use a controlled server/CDN integration; don’t paste these snippets into theme.liquid. CloudFront likewise needs its own server-side adapter and secret-management plan.

Partner API reference → · Frequently asked questions →