Developers
Hosted and embed
Configure a hosted link or classic cross-origin embed with deliberate activation and exact origins.
Hosted links
Use the issued service origin with /experience.html?integration=YOUR_INTEGRATION_ID. For one-property exploration, add the current published item ID as the item parameter. IDs are public routing identifiers, not credentials. Keep your normal property page available if Overa cannot load.
Classic embed v1
Load /overa-embed-v1.js from the issued HTTPS service origin, then call window.OveraEmbedV1.mount with a current container and exactly one integration ID. Register the exact parent origin before use. Permit the issued script and frame origins in your site's CSP; do not use a wildcard to bypass an origin failure.
export function attachExperience({
container, origin, integrationId, openButton, stopButton, showError,
}) {
// First load the classic /overa-embed-v1.js script from your issued origin.
// Keep the published parent origin registered. Never include a backend key.
const embed = window.OveraEmbedV1.mount({
container, origin, integrationId, title: 'Property discovery',
});
const reportError = error => showError(error.code || 'embed_unavailable');
embed.ready.catch(reportError);
const open = () => { embed.activate().catch(reportError); };
const stop = () => { embed.deactivate().catch(reportError); };
openButton.addEventListener('click', open);
stopButton.addEventListener('click', stop);
return () => {
openButton.removeEventListener('click', open);
stopButton.removeEventListener('click', stop);
embed.destroy();
};
}Lifecycle and failure handling
Mounting sets up the iframe. The host controls deliberate activation and deactivation. Catch readiness and action failures, keep a useful visible fallback, and call destroy() when the container is retired. retry() replaces a failed startup attempt; it is not permission to replay a chargeable journey automatically.
Supported events are ready, selection, item-action, source-state and error. Subscribe through the instance API and dispose the returned subscription when no longer needed. Handle only the current instance and exact registered origins; do not invent a second messaging protocol.
Browser authority
The configured renderer bootstraps a bounded published visitor session. Visitor authority stays in memory and travels in X-Overa-Visitor, not a URL, embed snippet or browser storage. A backend or operator preview credential must never be placed in this public example. Third-party cookies are not a prerequisite.
Use your own approved configuration.
Ask about the source, scope and delivery mode you need. Documentation does not activate an account or a provider allowance.
Request access