Skip to content
Published

Last reviewed: 2026-09-24

Public trust badge

Embed a CodeCleared trust badge on customer websites, with localized labels, optional compliance score, inactive-subscription state, and a public landing page.

What it is

Paid plans (Starter and above) can create public trust badges and embed them on showcase websites. Each badge has its own token, language (en / fr), visual style (pill or hex seal), public display name, and optional compliance score line.

The badge image is served from the API (brand blues + CodeCleared logo mark). The hex seal is taller than the pill — check layout where you embed. Clicks open a storefront landing page that shows the configured display name and a short explanation of the badge — with an optional free-account CTA.

Active vs inactive

StateBadge label (EN)When
ActiveSecured by CodeClearedBadge enabled, parent plan ≠ Free, no unresolved subscription payment failure
InactiveInactive subscriptionFree plan, payment failed, or badge disabled

Inactive badges stay embeddable (grey) so customer sites do not break.

Settings

In the app: Settings → Public Trust Badge.

  • Create up to 10 badges per organization
  • Configure a name (Settings list only), public display name, locale, style (pill or hex seal; new badges default to hex), enable flag, show-score flag
  • Copy HTML / Markdown snippets and the landing URL
  • Embed formats in Settings (tabs): image URL, HTML, Markdown, landing URL, JSON
  • Regenerate token (invalidates old embeds)
  • View impression and click counters (last 30 days)

Impressions count SVG loads; clicks count landing page views. Counts are anonymous (no visitor IP). Browser or CDN cache may under-count impressions.

What it is not

The badge and landing page are not a certification, attestation, or guarantee. Optional scores use the same Dependency Advisor compliance average as the product dashboard. See Compliance score.

Do not confuse this feature with Public notices (product status messages) or in-app Public Notice Disclosures (OSS NOTICE file sharing).

Plans

publicTrustBadge is enabled on Starter, Team, and Regulated. Free cannot create or manage badges.

Ops / environment

VariableWherePurpose
API_PUBLIC_URLcorePublic API base for managed urls.svgUrl / urls.jsonUrl (must be reachable by browsers embedding the badge). Falls back to SSO_REDIRECT_BASE_URL then API_URL
STOREFRONT_URLcoreLanding URL base in managed badge payloads; also added to API CORS origins with FRONTEND_URL / ALLOWED_ORIGINS
VITE_STOREFRONT_URLfrontBase for HTML/Markdown embed snippets in Settings
VITE_API_URLfrontFallback SVG base when building snippets without API urls
NEXT_PUBLIC_API_URLstorefrontAPI base for public badge JSON + click tracking on /trust/?token=

Local: point each app at the others’ origins (e.g. storefront http://localhost:3000, API http://localhost:3000/api via API_PUBLIC_URL, app http://localhost:5173) and restart after changing env.

Public SVG/click endpoints apply a soft in-process rate limit per IP (not shared across replicas). Prefer edge/CDN limits for hard perimeter.

Related documentation