Skip to content
iAgentify

Guide

Limit the chat to your domains, and why

While the allowed domains list is empty, any website can show your chat and use up your credits. How to fill it in, what each entry covers and what it does not protect.

In the app:
Agents › your agent › Widget › Installation
Open the app
Reviewed on
4 min read
In this article

Allowed domains is the list of websites that may show your agent’s chat. While it is empty, the chat works on any website; once you add your domains, it works only on them. Fill it in as soon as the chat is installed.

Why fill it in

The chat code carries your agent’s public key, and anyone who visits your website can see it in the page’s code. That key is not a secret: it only identifies the agent. But with an empty list, whoever copies it can install your chat on their site, and every reply your agent gives there uses your credits.

With the list filled in, websites that are not on it cannot load the chat and spend none of your credits.

In the agent’s Channels tab, the Website card shows at a glance how things stand: your domains or Any website.

Add your domains

You need the Member, Admin or Owner role.

  1. Go to Agents and open your agent.

  2. Open the Widget tab and, inside it, Installation.

  3. Under Add domain, type your website’s domain, for example yourcompany.com. The domain only, without https:// or anything after the slash.

  4. Press Add. The domain moves to the list, with what it covers underneath: “Includes www.yourcompany.com”.

  5. Repeat steps 3 and 4 for each domain. You can also paste several at once, separated by spaces or commas.

  6. Press Save changes. “Widget saved” appears.

    The list does not apply until you save.

  7. Open your website in a private browser window and check that the chat is still there.

To remove a domain, press the remove button next to it and save the changes. There is room for up to 20 domains per agent. If the app answers that what you typed “is not a valid domain”, write it as yourcompany.com or *.yourcompany.com.

What each entry covers

You typeThe chat works onIt does not work on
yourcompany.comyourcompany.com and www.yourcompany.comOther subdomains, such as shop.yourcompany.com
www.yourcompany.comwww.yourcompany.comyourcompany.com without www, and the other subdomains
shop.yourcompany.comshop.yourcompany.comyourcompany.com and the other subdomains
*.yourcompany.comyourcompany.com and all its subdomainsOther domains, such as yourcompany.es

A rule applies to the whole domain, with all its pages: the chat cannot be limited to one particular page.

Which domains to include

  • Your website’s real domain, as it appears in the browser’s address bar.
  • Any other domain where the code is pasted: a shop on a different domain, a campaign page, the .es version as well as the .com.
  • The test address, if you test the chat there: a staging site of your own, such as staging.yourcompany.com, or the temporary address your platform gives you, such as yourshop.myshopify.com or yoursite.webflow.io. Type your full address, never a wildcard such as *.myshopify.com, which would allow the chat on every site of that platform.

The preview inside the app needs nothing: it always works, whatever the list says.

What a visitor sees on a website that is not on the list

Nothing. The chat does not load: no button and no error message appear on the page, and no credits are spent.

The same happens to your own website if you leave out one of its domains. If the chat disappears after you fill in the list, compare the exact address of the page with the entries, as explained in the chat does not appear on your website.

What it does not protect

The list stops another website from showing your chat to its visitors. It is not a password:

  • It does not hide the public key. The key stays visible in your website’s code. It gives no access to your account: all it does is open the chat as one more visitor.
  • It does not decide who writes. Anyone who visits your website can use the chat.
  • It does not stop someone with technical knowledge. The check relies on the page address that the browser reports. A program that is not a browser can pretend to be your website and send messages to your agent. What limits that abuse is the message limits iAgentify applies and your credit balance.
  • It does not affect WhatsApp or Instagram. It applies to the website chat only.

So it is worth looking at Usage now and then, where you see the credits spent each day and the breakdown By channel. Owners and admins also get a notice when credits are running low. If you see spending that does not match the visits to your website, write to us from Support.

More background in privacy: where data is stored and who can see it and in the free trial and credits.

Duplicated agents

When you use Duplicate, the copy keeps the original’s list of domains, along with the rest of the chat’s settings. It has its own code and starts as a Draft. If the copy is going to serve a different website, change its domains before you activate it.