# Install teem

You are installing teem in an existing application. teem owns and hosts the widget. Wire the
hosted widget into the application; do not generate, copy, vendor or reimplement it.

The person who sent you here supplied an organization key beginning with `pk_`. It is public and
belongs in HTML. They may also have supplied a signing secret beginning with `sk_`, which is
optional and stays on the server; step 2 says what it buys. Neither key is an agent access key.

Do not ask for a key the person did not give you, and do not treat a missing signing secret as an
incomplete install.

## 1. Load the hosted widget

Add this once to the shared layout, immediately before the closing `</body>` tag when practical:

```html
<script src="https://teem.so/t.js" data-organization="PUBLIC_KEY" defer></script>
```

Replace `PUBLIC_KEY` with the supplied `pk_...` value. Do not download `t.js`; its hosted URL is
how fixes reach every installation.

Run the application and open a page. Localhost counts. The teem Connect screen changes to
installed after the script completes its first valid bootstrap.

## 2. Identify the signed-in user

Call `identify()` wherever the application knows who is signed in:

```text
teem.identify({ id: user.id, name: user.name, email: user.email })
```

Sign it when you have the signing secret. The organization key sits in a script tag, so anyone
can open a console and call `identify()` with any address; the hash is what lets the team trust
the name. Compute a lowercase hexadecimal HMAC-SHA256 of the user's stable id on the server and
render the result beside the public fields:

```text
hash = HMAC_SHA256(user.id, TEEM_SIGNING_SECRET) # lowercase hex, server-side

teem.identify({
  id: user.id,
  name: user.name,
  email: user.email,
  hash: hash
})
```

Use your framework's HMAC helper or standard crypto library. Never put the signing secret in
browser JavaScript, HTML, source control or a public environment variable.

Signing is optional and nothing depends on it. Omit `hash` when the secret was not supplied, when
the application has no server-side session, or when the person installing would rather not wire a
secret yet. Those identities arrive as self-declared, the same as a name typed into the widget,
and are never shown to the team as verified. The install is complete either way; signing can be
added later without changing anything else.

## 3. Optional feedback link

Any existing Help or Feedback control may open the widget explicitly:

```js
teem.open("feedback")
```

The launcher already opens the widget, so this is optional. The feedback surface arrives after
chat; keeping this call in the host now does not require a later integration change.

## Verify

- Only one `t.js` tag exists across the rendered page.
- The organization key is present in `data-organization`.
- If you signed the identity, the signing secret appears only in server-side code or secret storage.
- The launcher opens with keyboard and pointer input.
- On a phone, the panel fills the viewport and the page behind it does not scroll.
- The teem Connect screen reports the live origin and page.

For agent access after installation, use the separate [MCP reference](https://teem.so/mcp.md)
and create an agent in Settings → API & MCP.
