The embed is a single <iframe> that renders our community map inside any page you control. Listings update automatically as owners add, edit, and verify them on the canonical site. You keep full control of the page chrome, header, footer, ads, and the rest of your visitor experience.

Before the snippet works you'll need a partner key — and a key needs a verified account. Four quick steps:

  1. 1 Create an account
  2. 2 Verify your email
  3. 3 Request a key
  4. 4 Paste the snippet

1. Quick start

Paste the snippet below into any page that lives on a domain we've registered for you. Replace YOUR-PARTNER-KEY with the key we issued.

<iframe
  src="https://honestybox.uk/embed?key=YOUR-PARTNER-KEY"
  width="100%"
  height="600"
  sandbox="allow-scripts allow-same-origin allow-popups"
  style="border: 0;"
  loading="lazy"
  title="HonestyBox.uk map"
></iframe>

That's the full integration. The embed handles its own loading, pin clustering, and detail views. If you don't already, add <meta name="viewport" content="width=device-width, initial-scale=1"> to your page <head> — without it mobile browsers render every page at ~980px CSS pixels, which keeps the embed above its mobile breakpoint and shows a desktop-style layout on phones.

2. Filtering your map

Want your embed to show only certain kinds of box — say baked goods and sweets, not flowers — or only certain areas? Your map's filters live in your partner console, not in the snippet. Pick the categories and areas you want and the change applies to your live embed within about 30 seconds. You never re-paste the snippet, and visitors see exactly the scope you set — they can't broaden past it.

Your snippet stays exactly as above: https://honestybox.uk/embed?key=YOUR-PARTNER-KEY. Manage your filters any time from the Partners link in your account menu, or contact us and we'll set them up.

3. Theming your map

You can re-tint the four brand surfaces of your embed — the search header, the map rail, the map pins, and the list sidebar — to match your site, all from your partner console (not the snippet). Pick your colours and they go live within about 30 seconds. Our "Powered by HonestyBox" badge stays on its own fixed, always- legible chip regardless of the colours you pick. Contact us if you'd like us to set your colours up.

4. What happens when a visitor clicks Claim

The detail pane inside the embed has two buttons — Open on HonestyBox.uk and Claim this listing. Both open the canonical listing page in a new tab. The Claim path lands the visitor in our claim flow on the canonical site, completes the verification there, and stamps the resulting claim with your partner key for attribution. If the visitor is already signed in on honestybox.uk, the new tab opens directly into the claim form with no signup prompt.

5. Attribution & what you can't change

  • The embed displays a small "Powered by HonestyBox.uk" badge at the bottom-left of the map. It can't be hidden or restyled via embed config — it's part of the shipped widget.
  • Clicks on attribution open honestybox.uk in a new tab. We track these as a measure of the embed's value back to the canonical site.
  • No advertising of any kind renders inside the iframe. Ads belong on your surrounding page. You keep all revenue from ads placed around the frame; we don't take a cut.

6. Recommended iframe sandbox attributes

The sandbox attribute restricts what the embed can do inside your page. We recommend:

sandbox="allow-scripts allow-same-origin allow-popups"
  • allow-scripts — required. The map is a JavaScript application; without this the iframe renders an empty page.
  • allow-same-origin — required. Lets the embed read its own cookies (for the visible-only anti-scrape gate) and load tile / listing data from our own domain.
  • allow-popups — required for the "Claim this listing" and "Open on HonestyBox.uk" handoffs. Without it, the new-tab opens silently fail and the visitor sees nothing happen on click.

We deliberately do not require allow-forms or allow-top-navigation — the iframe never submits forms cross-document or navigates your parent page.

7. Getting a key

Contact us with:

  • Your name and the project / publication the embed will live on.
  • The email address you registered with — so we can link the key to your account.
  • The domain(s) you want registered (e.g. example.com and any subdomains — we support single-level wildcards like *.example.com).
  • A rough sense of where on your site the embed will live.

We issue keys manually for now while the partnership pattern is still bedding in. Self-serve key issuance is on the roadmap once the model is proven.

8. Origin allowlist

Each key is locked to the partner domain(s) you registered. The embed will refuse to render if loaded inside an <iframe> on any other domain — that's a browser-enforced Content-Security-Policy: frame-ancestors check we apply per request, not a JS gate that can be bypassed.

You can add or remove domains yourself from your partner console (the Partners link in your account menu), or contact us and we'll do it. Changes propagate to all embed loads within about 60 seconds.

9. Contact

Partner support: Contact us

Replies usually land within a working day. For anything urgent (a broken embed, a registered domain change for a campaign starting in hours), say so in your message.