Embeddable widgets
One script tag, one div per widget. Isolated origin, no cookies, no tracking, light and dark themes.
The embed host is not configured in this environment
Widgets are served from a dedicated subdomain, and its address comes from configuration rather than from the code. Until it is set, this page shows the markup but cannot show a working script address.
Installation
Put one script tag anywhere on the page — it is loaded asynchronously and does not block rendering — and one container per widget. Nothing else is required: no build step, no package, no other library.
<div data-tapewire="rate" data-pair="eur-usd"></div>Containers added to the page later are not picked up automatically. Call Tapewire.renderAll() after inserting them, or Tapewire.render(element) for a single one.
Widgets
one container per widgetCurrency pair
The official reference rate for one pair, with its recorded range and the change against the previous observation. Reference rates only — never a tradable quote.
| Attribute | Required | Meaning |
|---|---|---|
data-pair | yes | Pair as base-quote, lowercase. Example: eur-usd. |
<div data-tapewire="rate" data-pair="eur-usd"></div>Company insider feed
The most recent insider transactions filed for one company, with shares, value and the gap between the transaction and its disclosure.
| Attribute | Required | Meaning |
|---|---|---|
data-company | yes | Company slug as it appears in the page address. |
data-rows | no | Rows to show, 1 to 20. Default 6. |
<div data-tapewire="insiders" data-company="apple-inc" data-rows="8"></div>Sanctions name check
A name checked against every sanctions list loaded here, with the match strength on every row and the list versions the answer is based on.
| Attribute | Required | Meaning |
|---|---|---|
data-q | yes | Name to check. |
data-rows | no | Rows to show, 1 to 20. Default 5. |
<div data-tapewire="sanctions" data-q="ivan petrov" data-rows="5"></div>Attributes accepted by every widget
| Attribute | Meaning |
|---|---|
data-theme | auto, light or dark. Default auto: the widget follows the reader’s system setting. If your page marks its theme with data-theme on the html element, the widget picks that up without any configuration. |
data-height | Height in pixels. Without it the height is computed from the widget and the row count, and content that does not fit scrolls inside the frame rather than being cut off. |
A complete page
<!doctype html>
<html lang="en" data-theme="dark">
<body>
<div data-tapewire="rate" data-pair="eur-usd"></div>
<div data-tapewire="insiders"
data-company="apple-inc"
data-rows="8"></div>
<div data-tapewire="sanctions"
data-q="ivan petrov"
data-theme="light"></div>
<script src="/embed.js" async></script>
</body>
</html>The first two widgets follow the page theme because the html element declares it. The third overrides it explicitly.
Loading behaviour
- Nothing is requested while a widget is off screen. The frame address is set only when the container comes within half a screen of the viewport, and the frame itself is marked for lazy loading, so browsers without an intersection observer behave the same.
- The script is under 20 KB and has no dependencies. It reads its own address to find the widget host, so there is no domain written into it and nothing to reconfigure if you copy the tag between environments.
- Frames run without
allow-same-originand withoutallow-scripts. A widget cannot set a cookie, cannot read storage and cannot execute code on your page or its own. Every widget is complete server-rendered HTML, so this costs nothing. - No analytics, no tracking pixel, no fingerprinting. Requests carry the referring origin only because browsers send it; nothing is stored against a visitor.
Serving requirements
for whoever operates the deploymentWidgets are served from a dedicated host so that a compromise of an embedding page cannot reach the main site. That host must answer with headers that allow framing:
Content-Security-Policywithframe-ancestors *, and script sources permitting the application's own bootstrap.- no
X-Frame-Options: DENYon the widget host — browsers honour it regardless of the policy above and the frame would stay blank. Set-Cookiestripped on the widget host, so the isolation is enforced by the perimeter and not only by the sandbox attribute.
Terms
Widgets are free to embed on any page, including a commercial one, as long as the source attribution and the link back to investment.com stay visible. They are rendered inside the frame, so nothing is asked of you beyond not framing the widget in a way that hides them. The data itself carries the terms of its own source, named on every widget.