Skip to main content
Deploy your analytics in your frontend by embedding your application as an iFrame. An application renders the current user’s space — the dashboards and charts they have access to. Please click on the Deploy button in the Hub.
Hero LightHero Dark
You will need a project user token (JWT) for the current user and your application ID to render the correct space. The token is generated by following the steps in Backend Setup. The application ID is found in your application settings, or in the URL when viewing the application: /projects/{projectId}/applications/{applicationId}.
Important: Changing the JWT token in the iframe src will cause the browser to reload the entire iframe. This happens automatically when:
  • The JWT expires and gets refreshed
  • User switches organizations
  • User permissions are updated
Plan your token refresh strategy to minimize user disruption.
Below is an example of deploying the application with a JWT using Clerk middleware:

Understanding JWT Changes and Iframe Refresh

When the upsolveToken value changes in the code above, React will re-render the component with a new src URL for the iframe. This causes the browser to completely reload the iframe content.
Common scenarios that trigger iframe reload:
  • Automatic token refresh (every hour)
  • User switches between organizations
  • User logs out and back in
  • User permissions are updated
To improve user experience during token updates: 1. Cache the previous token until just before expiration 2. Show a loading overlay during refresh 3. Coordinate token updates during natural breaks in user workflow
For databases with Row-Level Security policies (Postgres, Redshift, or Supabase), you need to include a database auth token (dbAuthToken) in the iFrame src URL. This token identifies the current user and is used by your database’s RLS policies to filter data at the row level.Example updated iFrame URL:
  • dbAuthToken: The user-specific identifier that your RLS policies use for row-level filtering

For Postgres and Redshift

The dbAuthToken should contain the value that matches your RLS session variable (e.g., tenant ID, user ID, or company code):
Learn more about setting up RLS for Postgres and Redshift in the RLS & Schema Filtering guide.

For Supabase

To retrieve the Supabase session token (dbAuthToken), you can use Supabase’s auth.getSession method:
Refer to the Supabase API docs for more details on managing sessions and tokens.

Application Query Parameters

The application iframe supports the following query parameters:
The application iframe has no theme parameter. Its colors, fonts and light/dark styling come from the application’s theme, which you set in the Hub; every embed of the application uses it. (The AI chat embed below does accept theme.)
To embed one dashboard when you only have its ID (for example, the ID you passed to <UpsolveDashboard />), use /share/dashboard/{dashboardId}?jwt=…. It looks up the dashboard’s application and opens it as above, keeping every other parameter. See Migrate from v1 to v2.

Deploying AI Chat

Deploy AI chat in your frontend by embedding it as an iFrame. You’ll need a project user token (JWT) for the current user and the workspace ID to render the chat interface. The token is generated by following the steps in Backend Setup.

Getting the workspace ID

You can find your workspace ID in the workspace URL — /projects/{projectId}/workspaces/{workspaceId} — or in the embed snippet on the workspace’s Deploy page, which builds the iframe for you.
A workspace's Deploy page with the embed code and preview link generator
Authentication via JWT: Chat iframes use JWT tokens passed via query parameters for authentication, similar to applications. Users don’t need to be logged into the Hub - they just need a valid JWT token in the URL.
Important: Changing the JWT token in the iframe src will cause the browser to reload the entire iframe and reset the chat session. This happens automatically when:
  • The JWT expires and gets refreshed
  • User switches organizations
  • User permissions are updated
Each iframe load starts a fresh chat session. Plan your token refresh strategy carefully to avoid interrupting active conversations.
Below is an example of deploying chat with JWT using Clerk middleware:

Chat Query Parameters

The chat iframe supports the following query parameters:

Example with Initial Prompt

Admin Mode

Legacy /share/chat/{agentId} embeds can run in admin mode by setting isAdmin=true, which enables detailed tool execution information:
Workspace embeds (/share/workspace/...) always render the end-user view. To inspect tool calls and traces as a builder, use the workspace’s Playground instead.

Understanding Session Reset on JWT Change

When the upsolveToken value changes, React re-renders the iframe with a new src URL. This causes the browser to completely reload the iframe and start a new chat session.
Common scenarios that trigger session reset:
  • Automatic token refresh (every hour)
  • User switches between organizations
  • User logs out and back in
  • User permissions are updated
To preserve chat history across token refreshes, consider: 1. Implementing session persistence on your backend 2. Storing conversation history outside the iframe 3. Refreshing tokens during natural conversation breaks 4. Warning users before token expiration