Enterprise Integration Snippets
Verify ownership, generate a domain-scoped Enterprise API key, and publish your approved context before connecting your server. These examples require adaptation and testing against your own routing and security policies.
Security & Compliance Standards
- Zero User-Agent Spoofing: Delivery is triggered by explicit HTTP content negotiation (Accept: text/markdown). Your WAF rules remain in control.
- Domain-Scoped API Keys: Keys are stored as cryptographic hashes and restricted to exact hostnames.
- Fail-Open Architecture: These adapters fall back to your standard HTML origin if the API fails or times out.
Shared request handler
Include this helper alongside either adapter below. Replace the hostname and public-path allowlist. Do not forward credentials, session cookies or API keys to the origin. Outbound Optiview fetches carry a loop marker; the helper serves the origin for those requests.
// Server-side only. Store the key in an environment secret.
async function optimized(request, key, fallback) {
const url = new URL(request.url);
// Scope to a public-page allowlist for your own site.
if (url.hostname !== 'www.your-domain.com' ||
!['/', '/product/'].includes(url.pathname) || url.search ||
request.method !== 'GET' || request.headers.has('Cookie') ||
request.headers.has('Authorization') ||
request.headers.has('X-Optiview-Fetch')) return fallback();
let md = 0, html = 0;
for (const part of (request.headers.get('Accept') || '').toLowerCase().split(',')) {
const [type, ...params] = part.trim().split(';');
const quality = params.find(p => p.trim().startsWith('q='));
const q = quality ? Number(quality.trim().slice(2)) : 1;
if (!Number.isFinite(q) || q < 0 || q > 1) continue;
if (type === 'text/markdown') md = q;
if (type === 'text/html') html = q;
}
if (!key || !md || md < html) return fallback();
try {
const r = await fetch('https://app.optiview.ai/api/v1/render', {
method: 'POST',
headers: {Authorization: 'Bearer ' + key, 'Content-Type': 'application/json'},
body: JSON.stringify({url: url.href}),
signal: AbortSignal.timeout(12000)
});
if (!r.ok) return fallback();
const data = await r.json();
if (!data.success || typeof data.payload !== 'string' ||
data.content_type !== 'text/markdown') return fallback();
return new Response(data.payload, {headers: {
'Content-Type': 'text/markdown; charset=utf-8',
'Vary': 'Accept', 'Cache-Control': 'no-store'
}});
} catch { return fallback(); }
}Vercel / Next.js
Use a server deployment that supports middleware. Newer Next.js versions may use the proxy convention; static exports cannot run this code. Keep the key server-side, without a NEXT_PUBLIC prefix.
import {NextResponse} from 'next/server';
// Include optimized() above.
export function middleware(request) {
return optimized(request, process.env.OPTIVIEW_API_KEY,
async () => NextResponse.next());
}
export const config = {matcher: ['/', '/product/']};Cloudflare Workers
// Include optimized() above.
export default {
fetch(request, env) {
return optimized(request, env.OPTIVIEW_API_KEY,
() => fetch(request));
}
};Cloudflare Pages — our own deployment
Optiview’s marketing site is a static Next.js export on Pages. Its Pages Function wraps the asset response with the same negotiation, loop bypass and fail-open pattern:
// functions/_middleware.ts; include optimized() above.
export const onRequest = ({request, env, next}) =>
optimized(request, env.OPTIVIEW_API_KEY, next);Standard cURL
curl https://app.optiview.ai/api/v1/render \
-H "Authorization: Bearer $OPTIVIEW_API_KEY" \
-H 'Content-Type: application/json' \
--data '{"url":"https://www.your-domain.com/product/"}'Security and deployment
Delivery follows explicit content negotiation. We do not require User-Agent spoofing, and API keys are strictly domain-scoped. A crawler name alone does not trigger delivery. Keep keys out of browser code and source control; honor failed API responses by serving the origin.
Shopify theme code cannot securely hold this key or intercept HTTP responses. Use a controlled server/CDN integration; don’t paste these snippets into theme.liquid. CloudFront likewise needs its own server-side adapter and secret-management plan.