Verified visitors. Recognise customers who are signed in to your site.
If your website has its own login, your server can sign the customer's email so the agent knows who it is talking to: their lead is created automatically, your team sees their name, and account actions need no extra code.
On this page
What it gives you
- A lead without asking: the customer's first message creates their lead from the verified email, even with lead capture off. Existing details are never overwritten.
- Names in the inbox: Conversations shows the customer's name or email instead of an anonymous visitor.
- Context: the agent can see up to 3 of the customer's earlier conversations. This only happens for a verified email, never for one typed into the chat.
- Shopify account actions without a code: cancelling an order, changing an address or looking up their orders works for an hour without the emailed one-time code.
You only need this for pages behind your own login, such as a customer portal or members area. It is not needed for lead capture.
Turn it on
- 1Open Deploy → Widget, choose Go live (or Install code) and expand Identity verification.
- 2Choose Enable identity verification. A signing secret is created for this agent.
- 3Copy the secret into your server's environment variables. Never put it in browser code or your website's HTML.
Sign the customer on your server
For each page view by a signed-in customer, your server computes user_hash: the hex HMAC-SHA256 of <email>:<ts> with your secret, where email is trimmed and lowercased and ts is the current Unix time in seconds. A signature is valid for 10 minutes.
import crypto from "node:crypto";
export function simplyboostIdentity(secret, email) {
const ts = Math.floor(Date.now() / 1000);
const message = `${email.trim().toLowerCase()}:${ts}`;
const user_hash = crypto.createHmac("sha256", secret).update(message).digest("hex");
return { ts, user_hash };
}import hashlib, hmac, time
def simplyboost_identity(secret: str, email: str) -> dict:
ts = int(time.time())
message = f"{email.strip().lower()}:{ts}".encode()
user_hash = hmac.new(secret.encode(), message, hashlib.sha256).hexdigest()
return {"ts": ts, "user_hash": user_hash}function simplyboost_identity(string $secret, string $email): array {
$ts = time();
$userHash = hash_hmac('sha256', strtolower(trim($email)) . ':' . $ts, $secret);
return ['ts' => $ts, 'user_hash' => $userHash];
}Pass it to the widget
On pages for signed-in customers, add the visitor to the widget's configuration before the widget script (the Go live panel has a Copy snippet for this):
<script>
window._CHATBOT_CONFIG_ = {
chat_bot_id: "YOUR_BOT_ID",
visitor: {
email: "sanne@studiolicht.nl",
name: "Sanne de Vries",
ts: 1791360000,
user_hash: "THE_HASH_FROM_YOUR_SERVER"
}
};
</script>| In a single-page app | |
|---|---|
window.SimplyBoost.identify({ email, name, ts, user_hash }) | After the customer signs in. Works before or after the widget has loaded. |
window.SimplyBoost.reset() | When they sign out: the chat starts again as an anonymous visitor. |
Only the email and timestamp are signed; the name is shown as given. On a Shopify store, signed-in customers are recognised automatically.
Test it
Under 3. Test your integration in the panel, enter an email and a timestamp (Use now), paste the user_hash your server produced and choose Verify hash. You see Verified or the reason it failed, for example a timestamp in milliseconds instead of seconds, or a hash of a different string.
Options
- Require sign-in to chat: visitors who are not verified are asked to sign in instead of getting an answer in the website chat.
- Only show the chat to signed-in customers: add the snippet only to your signed-in pages, or load it after login with
window.createChatWidget(). - Rotate secret creates a new secret; the old one stops working at once, so update your server straight away.
Verification never fails open: a missing, expired or wrong signature simply leaves the visitor anonymous. The secret is stored encrypted, and only owners and editors can see it.