October 4, 2026
The most convincing artifact a LiveGraph run produces is the run itself — nodes lighting up in order, an edge animating as a hop resolves, a run parking at an approval gate. Until now that artifact lived behind your login, which meant the standard industry workaround: a screenshot of a canvas, which is a canvas that already went inert, or a pasted log nobody reads.
Shared runs fix that. One API call mints a link — and anyone holding it sees a read-only, live-updating canvas of that run, no account required.
POST /runs/:id/share → { token, expiresAt, embedUrl }
<iframe src="https://livegraph.ai/embed/runs/<id>?t=<token>" />POST /runs/:id/share returns a token and a ready-made embedUrl. Drop the URL in an iframe — a docs page, an internal status board, a client deliverable — and it renders the run's canvas: the graph's topology laid out as you arranged it, each node tinted by its state (idle, running, done, failed), edges animating as hops resolve. While the run is live the embed updates in real time over a WebSocket, with a slow poll as backup. When it finishes, the canvas settles into the run's final state — still a better artifact than a screenshot, because the shape and the path taken are the story.
The token is stateless — a signed payload (run id + graph id + expiry) with an HMAC keyed by a domain-prefixed secret, so a share token can never collide with a session token. You choose the lifetime: anywhere from a minute to 24 hours, two hours by default. Expiry is the revocation story — nothing to revoke server-side because nothing is stored — and deleting the run or its graph ends the link early. Minting is owner/editor-only, and scoped API keys can carry just runs:share if you want a service (say, your SaaS backend) minting links on demand without broader access.
The public view is a whitelist decided in one place in the API, not a blacklist you have to keep trimming:
The same discipline applies to the plumbing. The embed endpoint is unauthenticated by design — the token is the grant, and it names exactly one run. A bad, expired, or wrong-run token all return the same 404, so the endpoint can't be probed for which runs exist. It's rate-limited, served no-store, and the live socket only ever carries the whitelisted event types (a hop dispatched, a run parked at approval) — never the event payloads.
And it's genuinely read-only: the canvas ignores drags, there are no actions, no “reroute this for me” for the person watching. Sharing a run changes what people can see, never what they can do — the steering stays with the people inside the workspace.
The first consumer is one of our own spawned products. Its scan page kicks off a LiveGraph run — four specialist engines fanning out over a user's request — and the visitor watching the scan sees the actual canvas behind it, embedded inline, updating as each engine finishes. “Your scan is running” became “here is your scan, running.” The trust difference between those two sentences is the whole feature.
Agent platforms have converged on logging as the answer to “what did it do” — traces you can query after the fact, if you know what to ask. Logs are for debugging. They are not for showing a client that their deliverable is mid-flight, or putting a status page next to a job that takes an hour, or letting a teammate watch a fix round self-heal without handing them your login.
A run people can watch is worth more than a log they can't. The topology is already the honest map of what's happening — sharing it turned out to be less a feature than the removal of an artificial wall. If your product already runs agents on LiveGraph, the embed is one POST away; if it doesn't, the live demo shows the same canvas the embed renders.