Security & privacy
An embed sits inside somebody else's product and carries their people. These are the rules that make that safe, in the order a reviewer tends to ask about them.
Framing#
/embed/<appId> is the one framable document, and its frame-ancestors is built from that app's registered origins on every request. Platform A cannot frame platform B's embed; nobody unregistered can frame anything; everything else in Huddles stays 'none'.
The token#
- Signed, not opaque — HS256 with your secret, verified here; the secret never leaves your server and is shown to you exactly once.
- Short-lived — fifteen minutes at most. A replay inside that window buys the same session it already bought.
- Never in a URL — it travels by postMessage to our origin only. A token in a URL is a token in a log.
The session#
The cookie is Partitioned, SameSite=None and Secure: scoped to (your site × ours), invisible to your page, alive in every browser that has ended third-party cookies. Your JavaScript can never read it.
Identity#
A Huddles user is derived from (appId, sub). We store the display name you sent and nothing else about them — no email, no profile — and the same id every visit is what gives them a stable face and their own boards. A walk-in is a cookie with a numbered name; clearing it is forgetting them.
Counts, never rosters#
Every route your page can call answers with numbers. /presence says how many are here; /conversation/:key says whether a thread's huddle is open and how many are in it. Who they are is on your side of the page already.
Threads stay yours#
A conversation key is namespaced by your app and checked against your space on the socket. No page can name another platform's thread, and the key is never shown to anyone in the huddle.
What the island cannot do#
Shaping removes affordances; it is not a sandbox. The popOut key removes the way into the whole product; the operator's own switches outrank every app. Media permissions are delegated into the iframe by the widget's allow attribute — microphone, camera, screen — and the browser still asks the person.
huddles.space · Blog · For Mac · Premium · Terms · Privacy · © 2026 Huddles.Space