SupportlyDocs

Domains and keys

Use the existing Supportly screens and your authorized workspace. The feature sections below include setup guidance and a local prompt builder for each workflow.

Verified domains

Add a hostname, publish the displayed DNS TXT challenge, verify ownership, and set exact allowed origins on the widget key. Include subdomains only when explicitly enabled.

Permissions: Owner/admin (manage_api_keys). Plan: All plans, subject to widget-domain limits. Use /settings/domains.

  • Unverified and withdrawn domains cannot access customer sessions
  • Origins include the correct scheme and port
  • Cross-workspace domain assertions fail

Public and private keys

Use public_widget keys for embeds. Create server_identity keys only for the website backend, store them in private environment variables, and capture the secret once. Private keys default to 1 year (365 days), with 1-month, 3-month, 6-month, custom-day and explicitly dangerous no-expiry options and cap at 10 active keys per workspace. Rotation immediately revokes the previous key.

Permissions: Active owner/admin with manage_api_keys. Plan: Public keys on all plans; private server_identity keys on paid plans. Use /settings/api-keys.

  • Lists and activity logs expose prefixes and metadata only
  • Private keys are rejected by widget and dashboard endpoints
  • Revocation immediately stops subsequent customer access

Previous

Website auto login

Next

Customers and history