Browse the Help Centre

Your widget key and domain allowlist

Your widget key travels inside your web page, which means every visitor can read it. That is expected, and it is not what protects your account. The domain allowlist is.

Why the key is not a secret

Anything in a page a browser loads is readable by anyone who loads that page. Any "secret" shipped in front-end code is not one. Rather than pretend otherwise, the widget key is designed not to need secrecy: on its own it grants nothing.

What actually protects it

Every request from the widget is checked against the list of domains registered to your account. A request from a domain that is not on your list is refused.

Matching is done on the parsed origin — scheme, host and port — and never on text fragments. So yourcompany.com.example.net does not match yourcompany.com, which is exactly the trick a text comparison would fall for. A wildcard entry such as https://*.yourcompany.com matches subdomains at any depth but not the bare domain, which has to be listed separately if you use it.

When a request is refused, the refused domain is not echoed back in the response.

What to put on your list

Every domain your widget genuinely appears on:

  • your main site, with the exact scheme
  • www and bare variants, if you serve both
  • any regional or country domains
  • your staging site, if you want to test there
  • your local development address, if your team develops against it

Anything not on the list is refused, so an incomplete list shows up immediately as a widget that does not load.

If your widget key leaks

There is nothing to do, and nothing has happened. A key used from a domain that is not yours is refused. If you want it rotated anyway, email support@usekaras.com — but the key appearing somewhere public is not itself an incident.

What is not protected by the allowlist

A browser is what the allowlist governs. A scripted client outside a browser can claim any origin it likes, so the allowlist should be understood as preventing your key being used on someone else's website, not as an authentication mechanism. Rate limits bound what any caller can do — see Rate limits.

Adding or removing a domain

Email support@usekaras.com. Changes take effect within a few minutes.