Feature guides
Domains and keys
Use the existing Supportly screens and your authorized workspace. The feature sections below include setup guidance and a local prompt builder for each workflow.
Verified domains
Add a hostname, publish the displayed DNS TXT challenge, verify ownership, and set exact allowed origins on the widget key. Include subdomains only when explicitly enabled.
Permissions: Owner/admin (manage_api_keys). Plan: All plans, subject to widget-domain limits. Use /settings/domains.
- Unverified and withdrawn domains cannot access customer sessions
- Origins include the correct scheme and port
- Cross-workspace domain assertions fail
Public and private keys
Use public_widget keys for embeds. Create server_identity keys only for the website backend, store them in private environment variables, and capture the secret once. Private keys default to 1 year (365 days), with 1-month, 3-month, 6-month, custom-day and explicitly dangerous no-expiry options and cap at 10 active keys per workspace. Rotation immediately revokes the previous key.
Permissions: Active owner/admin with manage_api_keys. Plan: Public keys on all plans; private server_identity keys on paid plans. Use /settings/api-keys.
- Lists and activity logs expose prefixes and metadata only
- Private keys are rejected by widget and dashboard endpoints
- Revocation immediately stops subsequent customer access