heretic function. It runs once per page; later calls return the same run. result.requestId is a 32-character hex string. It is readable at GET /v1/verdict as soon as the promise resolves.
The site key is public. It attributes the session to a site and reads nothing.
Content security policy
dist/heretic.js from the npm package and name your origin in script-src.
Options and result lists every heretic(config) option and the result shape.