Skip to content

Fill gaps from assistant conversations: HighLevel app type and frontend API key exposure - #688

Open
mintlify[bot] wants to merge 2 commits into
mainfrom
mintlify/a3fbaf48
Open

Fill gaps from assistant conversations: HighLevel app type and frontend API key exposure#688
mintlify[bot] wants to merge 2 commits into
mainfrom
mintlify/a3fbaf48

Conversation

@mintlify

@mintlify mintlify Bot commented Aug 10, 2026

Copy link
Copy Markdown

Summary

Address two recurring assistant conversation themes by clarifying existing pages: users configuring HighLevel with the wrong App Type, and users unsure whether frontend API keys are exposed in production.

Changes

  • provider-guides/highlevel.mdx: Added a <Warning> under step 4 of app creation stating that HighLevel apps must be Public. Private apps do not support the OAuth redirect URL and client credential flow Ampersand uses, and cannot be connected.
  • embeddable-ui-components.mdx: Added a <Warning> in the API key authentication section explaining that keys passed to AmpersandProvider are visible in browser network requests and JavaScript, are not time-bound, and are not user-scoped. Directs production readers to JWT authentication.

Context

Assistant query buckets in the last week showed:

  • A user asked whether a HighLevel Private app would work, which it does not.
  • Two separate buckets asked about API key exposure in the browser and the associated risk in production.
    Both were answered correctly by the assistant, but the source pages did not state these points explicitly.

@mintlify

mintlify Bot commented Aug 10, 2026

Copy link
Copy Markdown
Author

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated (UTC)
Ampersand 🟢 Ready View Preview Aug 10, 2026, 4:12 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants