Partner embed
The embed is a single <iframe> that renders
our community map inside any page you control. Listings update
automatically as owners add, edit, and verify them on the
canonical site. You keep full control of the page chrome, header,
footer, ads, and the rest of your visitor experience.
Before the snippet works you'll need a partner key — and a key needs a verified account. Four quick steps:
1. Quick start
Paste the snippet below into any page that lives on a domain
we've registered for you. Replace YOUR-PARTNER-KEY with the key we issued.
<iframe
src="https://honestybox.uk/embed?key=YOUR-PARTNER-KEY"
width="100%"
height="600"
sandbox="allow-scripts allow-same-origin allow-popups"
style="border: 0;"
loading="lazy"
title="HonestyBox.uk map"
></iframe> That's the full integration. The embed handles its own loading,
pin clustering, and detail views. If you don't already, add <meta name="viewport" content="width=device-width, initial-scale=1"> to your page <head> — without it mobile
browsers render every page at ~980px CSS pixels, which keeps the
embed above its mobile breakpoint and shows a desktop-style
layout on phones.
2. Filtering your map
Want your embed to show only certain kinds of box — say baked goods and sweets, not flowers — or only certain areas? Your map's filters live in your partner console, not in the snippet. Pick the categories and areas you want and the change applies to your live embed within about 30 seconds. You never re-paste the snippet, and visitors see exactly the scope you set — they can't broaden past it.
Your snippet stays exactly as above: https://honestybox.uk/embed?key=YOUR-PARTNER-KEY. Manage
your filters any time from the Partners link in your
account menu, or contact us and we'll set them up.
3. Theming your map
You can re-tint the four brand surfaces of your embed — the search header, the map rail, the map pins, and the list sidebar — to match your site, all from your partner console (not the snippet). Pick your colours and they go live within about 30 seconds. Our "Powered by HonestyBox" badge stays on its own fixed, always- legible chip regardless of the colours you pick. Contact us if you'd like us to set your colours up.
4. What happens when a visitor clicks Claim
The detail pane inside the embed has two buttons — Open on HonestyBox.uk and Claim this listing. Both open the canonical listing page in a new tab. The Claim path lands the visitor in our claim flow on the canonical site, completes the verification there, and stamps the resulting claim with your partner key for attribution. If the visitor is already signed in on honestybox.uk, the new tab opens directly into the claim form with no signup prompt.
5. Attribution & what you can't change
- The embed displays a small "Powered by HonestyBox.uk" badge at the bottom-left of the map. It can't be hidden or restyled via embed config — it's part of the shipped widget.
- Clicks on attribution open
honestybox.ukin a new tab. We track these as a measure of the embed's value back to the canonical site. - No advertising of any kind renders inside the iframe. Ads belong on your surrounding page. You keep all revenue from ads placed around the frame; we don't take a cut.
6. Recommended iframe sandbox attributes
The sandbox attribute restricts what the embed can
do inside your page. We recommend:
sandbox="allow-scripts allow-same-origin allow-popups" allow-scripts— required. The map is a JavaScript application; without this the iframe renders an empty page.allow-same-origin— required. Lets the embed read its own cookies (for the visible-only anti-scrape gate) and load tile / listing data from our own domain.allow-popups— required for the "Claim this listing" and "Open on HonestyBox.uk" handoffs. Without it, the new-tab opens silently fail and the visitor sees nothing happen on click.
We deliberately do not require allow-forms or allow-top-navigation — the iframe never submits
forms cross-document or navigates your parent page.
7. Getting a key
Contact us with:
- Your name and the project / publication the embed will live on.
- The email address you registered with — so we can link the key to your account.
- The domain(s) you want registered (e.g.
example.comand any subdomains — we support single-level wildcards like*.example.com). - A rough sense of where on your site the embed will live.
We issue keys manually for now while the partnership pattern is still bedding in. Self-serve key issuance is on the roadmap once the model is proven.
8. Origin allowlist
Each key is locked to the partner domain(s) you registered. The
embed will refuse to render if loaded inside an <iframe> on any other domain — that's a
browser-enforced Content-Security-Policy: frame-ancestors check we
apply per request, not a JS gate that can be bypassed.
You can add or remove domains yourself from your partner console (the Partners link in your account menu), or contact us and we'll do it. Changes propagate to all embed loads within about 60 seconds.
9. Contact
Partner support: Contact us
Replies usually land within a working day. For anything urgent (a broken embed, a registered domain change for a campaign starting in hours), say so in your message.
Still have questions about the embed? Drop us a line and a real person will read it.
Get in touch