Getting Started

/

Create an Integration

Create an Integration

An integration gives your product a public key and a secret key. Use these keys to create embed sessions for your Scenes. Viewer Embeds, Editor Embeds, and the REST API all use the same integration credentials.

Create your first integration

  1. Sign in to Moshpit Studio.
  2. Open Integrations from the editor or your account menu.
  3. Choose Create integration and enter a Product name, such as Acme Storefront. This name identifies the integration everywhere in Studio.
  4. Optionally enter the website domain that will host it. You can add or change the domain later.
  5. Create the integration, then copy the msk_ secret immediately. Moshpit only displays it once. Save the mpk_ public key alongside it.

You can also create additional integrations or rotate keys from the same modal.

What you get

Each integration provides two keys:

CredentialFormatWhere it lives
Public keympk_ + 24+ base64url charsBrowser HTML, env var, public code
Secret keymsk_ + 32+ base64url charsServer only

After creation, only the last four characters of the secret are visible in the Integrations UI. If you lose the secret, rotate it instead of trying to recover it.

Product name and website domain

Every new integration requires a Product name. Studio uses that name in integration cards, selectors, and Scene ownership labels so credentials stay recognizable as your account grows.

The Website domain is optional. You can paste a full URL (https://app.example.com/editor) or a bare host (app.example.com); Moshpit saves only the lowercase host as productSlug.

This domain is metadata and a product boundary for Scenes created through the integration. It does not enforce browser origin or host-domain restrictions by itself.

Capabilities

Each integration has a stored set of capabilities, and older integrations may still show both viewer and editor. Effective access is also checked against the integration owner's plan.

  • Free accounts can mint viewer sessions only; viewer session mints are unmetered.
  • Pro accounts can mint watermark-free viewer sessions and use the REST API.
  • Enterprise accounts can mint viewer and editor sessions and use the REST API.

When you call POST /api/editor/embed-sessions, specify which type of session you want. Moshpit verifies both the integration capability and the owner's plan entitlement.

Bind a default Scene (optional)

Set a default Scene if your integration usually embeds the same Scene. When a default Scene is set, viewer sessions minted without a splatId will use it.

A session with an explicit splatId uses that Scene instead of the default. The Scene must belong to the integration owner.

Rotate keys

Both keys can be rotated from the Integrations UI:

  • Rotating the public key invalidates iframes that hard-code the old mpk_ value. Use only if the public key has been associated with a host you no longer trust.
  • Rotating the secret key invalidates the old msk_ immediately. Existing sessions remain valid until their JWT expires, but no new ones can be minted. Always rotate the secret if you suspect leakage.

Keep secrets out of git

Store msk_ keys in your platform's secret manager or server environment. Never commit them to a repository.

What's next