Domains & security

Control where your widget is allowed to run.

Domain allowlist

In chatbot Settings, add one domain per line (e.g. example.com or www.example.com). When the list is non-empty, the widget only serves visitors on those hosts. Leave the list empty during local development if you test on localhost.

  • Use the exact host visitors see in the browser address bar.
  • Include both apex and www if you use both.
  • Subdomains must be listed separately unless you only embed on the parent marketing site.

Widget embed website

The embed website field in Settings is the primary site where you install the script. It helps your team remember the production URL and is used alongside knowledge-base website sources (which can be different URLs).