Everything inside a teal frame is a real Nash widget in a cross-origin iframe. Everything else — the nav, the filters, the ERP table — is host chrome this page renders itself. Selection, filters and ETAs cross the boundary as messages; the console below records every one of them.
Allow-list this origin first. In your Nash
Portal, add under Settings →
Widgets → Allowed origins. Nash verifies it on every mint and
refuses everything without it, so a credential from an
organization that has not done this renders nothing here — that
is the check, not a fault in the demo. Leave the field empty to
keep the deployment's default demo organization.
Held for this tab only — sessionStorage plus a session cookie the token endpoints read — and gone when the tab closes. It never appears in a URL, in the page bundle, in the protocol inspector, or in any response body.
Ids must belong to the organization above — the credential's, or the
demo organization when no credential is set. Nash denies anything
else with a uniform FORBIDDEN at mint. Your set is
saved in this browser only (localStorage, plus a cookie the token
endpoints read) and never appears in a URL. Applying verifies the
combination with one real mint, then re-creates the widgets so
fresh sessions seal it.