Skip to content
Aletheca

Embed

One script tag. Your interface, your domain, our pipeline.

The embed renders into your page rather than an iframe and inherits CSS custom properties where you allow it. Your content-security policy must permit the script and its authored style element.

Anywhere in the page
<script
  src="https://aletheca.com/embed/v1.js"
  data-partner-token="<issued by Aletheca>"
  data-theme="inherit"
  async
></script>

Surfaces

Each surface is a div with a data-aletheca attribute. The script scans on load and on DOM mutation, so surfaces rendered by your own framework are picked up without a second call.

  • data-aletheca="request-button"

    The workhorse. Opens the composer pre-filled from whatever the page is about — a case, a place, a person. Your site never touches a letter, a card or an agency. Every prefill is editable and untrusted: the title caps at 200 characters, scope at 2,000, location at 200, and records window must be two ISO dates. A partner-owned reference belongs in the signed handoff token, not an editable attribute.

    data-agencydata-prefill-titledata-prefill-scopedata-prefill-window-startdata-prefill-window-enddata-prefill-locationdata-campaigndata-label
  • data-aletheca="docket"

    The public funding queue. Readers follow a proposal to Aletheca for the authenticated contribution flow; payment never happens in the host page.

    data-campaigndata-statusdata-limitdata-sort
  • data-aletheca="campaign"

    A campaign summary with its live funding progress and a hosted Aletheca contribution handoff.

    data-campaign
  • data-aletheca="request"

    One request's live status: disposition, statutory clock, and the last few ledger events. Drop it on a case page and it updates itself as the agency moves.

    data-request
  • data-aletheca="feed"

    The public activity ledger. The current embed supports a result limit; partner-filtered ledgers are not mounted yet.

    data-limit

A case page, end to end

uap.nexus/cases/2026-03-11
<div
  data-aletheca="request-button"
  data-agency="faa"
  data-prefill-title="Radar and ATC audio, SLC sector, 11 Mar 2026"
  data-prefill-scope="All radar data (NTAP or equivalent), controller
    audio recordings and position reports for Salt Lake City ARTCC
    sectors 14 and 16 between 0200Z and 0500Z on 11 March 2026."
  data-prefill-window-start="2026-03-11"
  data-prefill-window-end="2026-03-12"
  data-prefill-location="Salt Lake City ARTCC, sectors 14 and 16"
  data-campaign="aaro-resolution-record"
  data-label="Request the records"
></div>

<div
  data-aletheca="request"
  data-request="ALT-2026-0097"
></div>

Theming

With data-theme="inherit" the embed reads your page’s computed colours and type. Override any of them explicitly, or set data-theme="aletheca" to keep the archive’s own dialect, which is the right choice when the embed should read as a citation rather than as part of your interface.

CSS custom properties
.aletheca-embed {
  --alx-bg: transparent;
  --alx-fg: var(--your-text);
  --alx-accent: var(--your-accent);
  --alx-border: var(--your-hairline);
  --alx-radius: 6px;
  --alx-font: inherit;
}

What the embed will never do

    Track your readers

    No advertising identifiers, cross-site cookies, fingerprinting, reader identifier, or interaction state. Public reads omit credentials; authenticated actions happen on Aletheca.

    Take a payment in your DOM

    Card details are entered in a Stripe-hosted context, never in a field the embed rendered. Your site stays out of PCI scope entirely.

    Block your page

    The script is async and renders only when it finds a surface. If a public API fetch fails after the script loads, that surface becomes a plain Aletheca link.

Server-side instead? The REST API exposes the public read contract and hosted write handoffs. Outbound partner webhooks are not mounted yet.