Guide
Limit the chat to your domains, and why
While the allowed domains list is empty, any website can show your chat and use up your credits. How to fill it in, what each entry covers and what it does not protect.
- Reviewed on
- 4 min read
In this article
Allowed domains is the list of websites that may show your agent’s chat. While it is empty, the chat works on any website; once you add your domains, it works only on them. Fill it in as soon as the chat is installed.
Why fill it in
The chat code carries your agent’s public key, and anyone who visits your website can see it in the page’s code. That key is not a secret: it only identifies the agent. But with an empty list, whoever copies it can install your chat on their site, and every reply your agent gives there uses your credits.
With the list filled in, websites that are not on it cannot load the chat and spend none of your credits.
In the agent’s Channels tab, the Website card shows at a glance how things stand: your domains or Any website.
Add your domains
You need the Member, Admin or Owner role.
Go to Agents and open your agent.
Open the Widget tab and, inside it, Installation.
Under Add domain, type your website’s domain, for example
yourcompany.com. The domain only, withouthttps://or anything after the slash.Press Add. The domain moves to the list, with what it covers underneath: “Includes www.yourcompany.com”.
Repeat steps 3 and 4 for each domain. You can also paste several at once, separated by spaces or commas.
Press Save changes. “Widget saved” appears.
The list does not apply until you save.
Open your website in a private browser window and check that the chat is still there.
To remove a domain, press the remove button next to it and save the changes. There is room for up to 20 domains per agent. If the app answers that what you typed “is not a valid domain”, write it as yourcompany.com or *.yourcompany.com.
What each entry covers
| You type | The chat works on | It does not work on |
|---|---|---|
yourcompany.com | yourcompany.com and www.yourcompany.com | Other subdomains, such as shop.yourcompany.com |
www.yourcompany.com | www.yourcompany.com | yourcompany.com without www, and the other subdomains |
shop.yourcompany.com | shop.yourcompany.com | yourcompany.com and the other subdomains |
*.yourcompany.com | yourcompany.com and all its subdomains | Other domains, such as yourcompany.es |
A rule applies to the whole domain, with all its pages: the chat cannot be limited to one particular page.
Which domains to include
- Your website’s real domain, as it appears in the browser’s address bar.
- Any other domain where the code is pasted: a shop on a different domain, a campaign page, the
.esversion as well as the.com. - The test address, if you test the chat there: a staging site of your own, such as
staging.yourcompany.com, or the temporary address your platform gives you, such asyourshop.myshopify.comoryoursite.webflow.io. Type your full address, never a wildcard such as*.myshopify.com, which would allow the chat on every site of that platform.
The preview inside the app needs nothing: it always works, whatever the list says.
What a visitor sees on a website that is not on the list
Nothing. The chat does not load: no button and no error message appear on the page, and no credits are spent.
The same happens to your own website if you leave out one of its domains. If the chat disappears after you fill in the list, compare the exact address of the page with the entries, as explained in the chat does not appear on your website.
What it does not protect
The list stops another website from showing your chat to its visitors. It is not a password:
- It does not hide the public key. The key stays visible in your website’s code. It gives no access to your account: all it does is open the chat as one more visitor.
- It does not decide who writes. Anyone who visits your website can use the chat.
- It does not stop someone with technical knowledge. The check relies on the page address that the browser reports. A program that is not a browser can pretend to be your website and send messages to your agent. What limits that abuse is the message limits iAgentify applies and your credit balance.
- It does not affect WhatsApp or Instagram. It applies to the website chat only.
So it is worth looking at Usage now and then, where you see the credits spent each day and the breakdown By channel. Owners and admins also get a notice when credits are running low. If you see spending that does not match the visits to your website, write to us from Support.
More background in privacy: where data is stored and who can see it and in the free trial and credits.
Duplicated agents
When you use Duplicate, the copy keeps the original’s list of domains, along with the rest of the chat’s settings. It has its own code and starts as a Draft. If the copy is going to serve a different website, change its domains before you activate it.
Related articles
- Install the chat on your websiteCopy the chat code from your agent’s Widget tab and paste it into your website. Includes the steps for a hand-built site and the guide for each platform.
- The chat does not appear on your website: what to checkIf the chat button does not show on your website, go through these causes in order: the agent, the code, the allowed domains, caching and whatever your site may be blocking.
- Privacy: where data is stored and who can see itYour data is hosted in the European Union and only your team sees it. What is sent to the AI to write a reply, which providers are involved and how to exercise your rights.
- The free trial and credits: what happens when they run outThe trial lasts 30 days and includes 300 credits, with no card. What uses credits, where to see your balance, and what happens when they run out or the trial ends.