Last reviewed: 2026-09-24
Public trust badge
Embed a CodeCleared trust badge on customer websites, with localized labels, optional compliance score, inactive-subscription state, and a public landing page.
What it is
Paid plans (Starter and above) can create public trust badges and embed them on showcase websites. Each badge has its own token, language (en / fr), visual style (pill or hex seal), public display name, and optional compliance score line.
The badge image is served from the API (brand blues + CodeCleared logo mark). The hex seal is taller than the pill — check layout where you embed. Clicks open a storefront landing page that shows the configured display name and a short explanation of the badge — with an optional free-account CTA.
Active vs inactive
| State | Badge label (EN) | When |
|---|---|---|
| Active | Secured by CodeCleared | Badge enabled, parent plan ≠ Free, no unresolved subscription payment failure |
| Inactive | Inactive subscription | Free plan, payment failed, or badge disabled |
Inactive badges stay embeddable (grey) so customer sites do not break.
Settings
In the app: Settings → Public Trust Badge.
- Create up to 10 badges per organization
- Configure a name (Settings list only), public display name, locale, style (
pillorhexseal; new badges default to hex), enable flag, show-score flag - Copy HTML / Markdown snippets and the landing URL
- Embed formats in Settings (tabs): image URL, HTML, Markdown, landing URL, JSON
- Regenerate token (invalidates old embeds)
- View impression and click counters (last 30 days)
Impressions count SVG loads; clicks count landing page views. Counts are anonymous (no visitor IP). Browser or CDN cache may under-count impressions.
What it is not
The badge and landing page are not a certification, attestation, or guarantee. Optional scores use the same Dependency Advisor compliance average as the product dashboard. See Compliance score.
Do not confuse this feature with Public notices (product status messages) or in-app Public Notice Disclosures (OSS NOTICE file sharing).
Plans
publicTrustBadge is enabled on Starter, Team, and Regulated. Free cannot create or manage badges.
Ops / environment
| Variable | Where | Purpose |
|---|---|---|
API_PUBLIC_URL | core | Public API base for managed urls.svgUrl / urls.jsonUrl (must be reachable by browsers embedding the badge). Falls back to SSO_REDIRECT_BASE_URL then API_URL |
STOREFRONT_URL | core | Landing URL base in managed badge payloads; also added to API CORS origins with FRONTEND_URL / ALLOWED_ORIGINS |
VITE_STOREFRONT_URL | front | Base for HTML/Markdown embed snippets in Settings |
VITE_API_URL | front | Fallback SVG base when building snippets without API urls |
NEXT_PUBLIC_API_URL | storefront | API base for public badge JSON + click tracking on /trust/?token= |
Local: point each app at the others’ origins (e.g. storefront http://localhost:3000, API http://localhost:3000/api via API_PUBLIC_URL, app http://localhost:5173) and restart after changing env.
Public SVG/click endpoints apply a soft in-process rate limit per IP (not shared across replicas). Prefer edge/CDN limits for hard perimeter.