> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boat.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# URLs, embedding and security

> What a desktop URL contains, how to embed the stream in your app, and how Boat protects the desktop.

## What happens when you open the desktop

1. The CLI or the dashboard asks Boat for a new signed-in desktop URL for your sandbox.
2. If the desktop stream is not ready, Boat prepares it.
3. Boat opens the browser viewer.

The URL opens a browser page. For the default Moonlight stream, the URL looks like this:

```text theme={null}
https://<sandbox-desktop-host>/stream.html?hostId=<host>&appId=<app>&theme=light#token=<token>
```

For a VNC stream (`--vnc`), the URL points to a noVNC page:

```text theme={null}
https://<sandbox-vnc-host>/vnc.html?autoconnect=true&password=<pw>&_token=<token>
```

Boat generates the host, the IDs, the password and the token for the running sandbox.

If you use `--public`, or send `publicAccess: true` to `POST /sandboxes/{sandboxId}/desktop?vnc=1`, the noVNC URL has no `_token`.

## How the Moonlight viewer handles the token

* The viewer removes the fragment from the URL at once.
* The viewer sends the token in authenticated request headers and in the first WebSocket frame.
* The viewer never puts the token in an HTTP or WebSocket request URL.

## Embed the stream in your app

To show the desktop inside your own product, put the default Moonlight URL in an `iframe`.

To hide the viewer overlay, add `overlay=0` to the query string. The side panel and the stats text then never show.

```text theme={null}
https://<sandbox-desktop-host>/stream.html?hostId=<host>&appId=<app>&theme=light&overlay=0#token=<token>
```

Add the parameter before the `#`. The token stays in the fragment.

## Security model

| Topic | Rule |
| - | - |
| How Boat makes a URL | Only through the authenticated Boat API. |
| URL lifetime | Ten minutes. |
| List and info responses | They do not cache or return a desktop URL. Call the desktop endpoint each time you open a stream. |
| Clipboard | Reads and writes work only with the credentials of the active desktop Moonlight stream. |
| Browser-only view | It has no clipboard routes. |

A desktop URL contains a desktop access token in its fragment. The URL can let a browser attach to that desktop session. Treat the URL as sensitive:

* Do not paste the full URL into shared chats or logs.
* To give another person access to a sandbox, use the correct Boat account and access controls. Do not share a desktop URL.

## After a stop, resume or fork

* When you stop or archive a sandbox, the desktop is not available. Resume the sandbox to use it again.
* Do not expect desktop processes to survive a resume or a fork. After a resume or a fork, open Chrome again and restart your app or dev server.
* The `computer` tools come back by themselves. Boat restarts the desktop daemon behind them with the sandbox.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.