Skip to content

Artifacts

An artifact is a document the assistant produces next to the conversation, such as a web page, a diagram or a file, that you can open, read and revise.

The assistant creates one with create_artifact and changes it with update_artifact. Each artifact has one of these kinds:

KindWhat it is
htmlA web page, rendered live
svgA vector image
markdownA formatted document
mermaidA diagram written in Mermaid syntax
codeA source file, shown as code

React components and design mockups are planned and are not rendered yet.

Every change makes a new version, and the earlier ones stay. The panel shows the artifact with its version number, and you can open an earlier version. The API returns the full list; see HTTP API.

Artifacts are rendered on a separate origin (WS_ARTIFACT_URL, port 8081 locally) inside an <iframe sandbox="allow-scripts">. The exception is the code kind, which the app shows as plain text in the page and does not run. The page can run its own scripts, but it cannot read the app’s cookies or storage, cannot make network requests, and cannot load images from the network, so a generated page cannot leak the conversation. Scripts may come from a short list of CDNs (cdnjs, jsDelivr, the Tailwind CDN and unpkg); stylesheets from cdnjs, jsDelivr and Google Fonts, and font files from cdnjs and Google Fonts. Web links (http and https) inside an artifact open in a new tab through the parent page. The links the app uses to show an artifact are signed and expire after 24 hours by default, and a single version is limited to 2 MiB.

Do not point the app and artifact hostnames at the same host. The reasons and the full policy are in Trust and security.

Checked against the code at master 3364287.