Preview URLs
The review badge lets reviewers pin feedback on your preview builds without installing the extension. Each project’s list of preview addresses decides where the badge can sign people in.
The list is under Project settings Review Links. Owners and admins manage it.
What the list controls
The badge is a script that runs on your site, so Skyelight uses this list to decide where it is allowed to work:
- Nobody can sign in through the badge on an address until it is on the list, even if the script is on the page.
- The address also tells Skyelight which project the feedback belongs to, so your code doesn’t need a project key.
- When you remove an address, every badge session on it stops at its next token refresh, within about five minutes.
Add a preview address
Add the badge to your preview builds
The recommended way is Skyelight Build. It adds the script to preview builds and keeps it out of production:
npx @skyelight/buildOr add the tag by hand to the pages you want reviewed:
<script type="module" src="https://app.skyelight.ai/a.js"></script>Add the address in Review Links
Click Add link and enter the address your previews are served from, such as
https://acme-git-main.vercel.app. If the preview is behind Vercel Deployment Protection, also add a bypass key. See Deployment bypass.Invite reviewers and send them the link
Invite reviewers to the workspace with the reviewer role, then send them the preview address. See Managing users.
Address rules
Skyelight compares the full origin: scheme, host and port.
- Wildcards aren’t accepted. Add each preview address as its own entry.
- Addresses must use
https, except local development addresses:localhost,127.0.0.1and*.localhostcan usehttp. - If the same address is listed on two projects, the script tag needs a
data-projectattribute that names the project.
How reviewers sign in
Reviewers always sign in with a Skyelight account. The badge has no anonymous mode.
- Links from Skyelight, such as notification emails, include
?skyelight=1, which starts the badge. - The first time, the badge sends the reviewer to Skyelight to sign in, then returns them to the page.
- After that, the browser stays signed in on that site for 30 days.
- Signing out from the badge menu ends the session on that site. Adding
?skyelight=0to the address does the same. - When you remove someone from the workspace, their badge stops working within about five minutes.
A badge session can reach only the project that its address belongs to.
Build status for each address
After a reviewer signs in on a build that uses Skyelight Build, that build’s address in Review Links shows what the build reported:
- Connected, beside the address
- The framework the site is built with
- The plugin version, shown as Build v followed by the number
- Tags for Stamp sources, Badge and Keep out of production
If the build is a production build, the last tag reads In production, with a warning that the badge shows publicly to visitors.
For visitors who aren’t reviewing, the badge loads about 1.5 kB, makes no network request and adds nothing to the page. See Privacy and CSP.