Guides: Verified visitors

Verified visitors. Recognise customers who are signed in to your site.

If your website has its own login, your server can sign the customer's email so the agent knows who it is talking to: their lead is created automatically, your team sees their name, and account actions need no extra code.

Identity verification
Widget → Go live
Verified
Visitorsanne@studiolicht.nl
Signedemail + timestamp, HMAC-SHA256
Valid for10 minutes
Require sign-in to chatOff
Your signature is correct

What it gives you

  • A lead without asking: the customer's first message creates their lead from the verified email, even with lead capture off. Existing details are never overwritten.
  • Names in the inbox: Conversations shows the customer's name or email instead of an anonymous visitor.
  • Context: the agent can see up to 3 of the customer's earlier conversations. This only happens for a verified email, never for one typed into the chat.
  • Shopify account actions without a code: cancelling an order, changing an address or looking up their orders works for an hour without the emailed one-time code.

You only need this for pages behind your own login, such as a customer portal or members area. It is not needed for lead capture.

Turn it on

  1. 1Open Deploy → Widget, choose Go live (or Install code) and expand Identity verification.
  2. 2Choose Enable identity verification. A signing secret is created for this agent.
  3. 3Copy the secret into your server's environment variables. Never put it in browser code or your website's HTML.

Sign the customer on your server

For each page view by a signed-in customer, your server computes user_hash: the hex HMAC-SHA256 of <email>:<ts> with your secret, where email is trimmed and lowercased and ts is the current Unix time in seconds. A signature is valid for 10 minutes.

Node.js
import crypto from "node:crypto";

export function simplyboostIdentity(secret, email) {
  const ts = Math.floor(Date.now() / 1000);
  const message = `${email.trim().toLowerCase()}:${ts}`;
  const user_hash = crypto.createHmac("sha256", secret).update(message).digest("hex");
  return { ts, user_hash };
}
Python
import hashlib, hmac, time

def simplyboost_identity(secret: str, email: str) -> dict:
    ts = int(time.time())
    message = f"{email.strip().lower()}:{ts}".encode()
    user_hash = hmac.new(secret.encode(), message, hashlib.sha256).hexdigest()
    return {"ts": ts, "user_hash": user_hash}
PHP
function simplyboost_identity(string $secret, string $email): array {
    $ts = time();
    $userHash = hash_hmac('sha256', strtolower(trim($email)) . ':' . $ts, $secret);
    return ['ts' => $ts, 'user_hash' => $userHash];
}

Pass it to the widget

On pages for signed-in customers, add the visitor to the widget's configuration before the widget script (the Go live panel has a Copy snippet for this):

<script>
  window._CHATBOT_CONFIG_ = {
    chat_bot_id: "YOUR_BOT_ID",
    visitor: {
      email: "sanne@studiolicht.nl",
      name: "Sanne de Vries",
      ts: 1791360000,
      user_hash: "THE_HASH_FROM_YOUR_SERVER"
    }
  };
</script>
In a single-page app
window.SimplyBoost.identify({ email, name, ts, user_hash })After the customer signs in. Works before or after the widget has loaded.
window.SimplyBoost.reset()When they sign out: the chat starts again as an anonymous visitor.

Only the email and timestamp are signed; the name is shown as given. On a Shopify store, signed-in customers are recognised automatically.

Test it

Under 3. Test your integration in the panel, enter an email and a timestamp (Use now), paste the user_hash your server produced and choose Verify hash. You see Verified or the reason it failed, for example a timestamp in milliseconds instead of seconds, or a hash of a different string.

Options

  • Require sign-in to chat: visitors who are not verified are asked to sign in instead of getting an answer in the website chat.
  • Only show the chat to signed-in customers: add the snippet only to your signed-in pages, or load it after login with window.createChatWidget().
  • Rotate secret creates a new secret; the old one stops working at once, so update your server straight away.

Verification never fails open: a missing, expired or wrong signature simply leaves the visitor anonymous. The secret is stored encrypted, and only owners and editors can see it.

Try SimplyBoost with your own content

Start a 7-day free trial with 100 AI replies. Add your website, install the widget and see how the agent answers your customers.

See pricing
  • No credit card required
  • 7 days, 100 AI replies
  • From €39 a month
  • Hosted in Europe