The pieces
What a site needs
- A site record, created in the NextIntent console or through
POST /v1/sdkwith a name and its allowed origins. This gives you thesite_idand the site’s public key. - The SDK script on every page. See Install the SDK.
- A facts sheet: what the site is willing to have said on its behalf. Without one, the engine still records moments but has nothing to say. See The facts sheet.
- A way to show the sentence: the card snippet, your own listener for the
nextintent:momentevent, or a popup tool. See The card and the event. - Commerce inputs, if you want orders credited to moments: the cart beacon on cart pages and an order feed from your platform. See Commerce endpoints.
The signal envelope
Every signal the SDK emits has the same shape on the bus:{ meta: { type, event_time, sdk_id, user_id, tab_id, source }, context: { page, ... }, payload }. Browser types come through the collector with source: "rtp"; commerce types (cart, order, refund, checkout, card, erase) come from the SDK service with source: "sdk". The engine refuses a commerce type from a browser source, so a page cannot claim an order happened.
Rate limits and origins
Public storefront routes are origin-gated: a request whoseOrigin is not on the site’s allowed list is refused before anything is read. The management API is limited to 600 requests a minute per key and 60 a minute per IP unauthenticated. See Authentication.
