Your widget key and domain allowlist
Your widget key travels inside your web page, which means every visitor can read it. That is expected, and it is not what protects your account. The domain allowlist is.
Why the key is not a secret
Anything in a page a browser loads is readable by anyone who loads that page. Any "secret" shipped in front-end code is not one. Rather than pretend otherwise, the widget key is designed not to need secrecy: on its own it grants nothing.
What actually protects it
Every request from the widget is checked against the list of domains registered to your account. A request from a domain that is not on your list is refused.
Matching is done on the parsed origin — scheme, host and port — and never on
text fragments. So yourcompany.com.example.net does not match
yourcompany.com, which is exactly the trick a text comparison would fall for.
A wildcard entry such as https://*.yourcompany.com matches subdomains at any
depth but not the bare domain, which has to be listed separately if you use it.
When a request is refused, the refused domain is not echoed back in the response.
What to put on your list
Every domain your widget genuinely appears on:
- your main site, with the exact scheme
wwwand bare variants, if you serve both- any regional or country domains
- your staging site, if you want to test there
- your local development address, if your team develops against it
Anything not on the list is refused, so an incomplete list shows up immediately as a widget that does not load.
If your widget key leaks
There is nothing to do, and nothing has happened. A key used from a domain that is not yours is refused. If you want it rotated anyway, email support@usekaras.com — but the key appearing somewhere public is not itself an incident.
What is not protected by the allowlist
A browser is what the allowlist governs. A scripted client outside a browser can claim any origin it likes, so the allowlist should be understood as preventing your key being used on someone else's website, not as an authentication mechanism. Rate limits bound what any caller can do — see Rate limits.
Adding or removing a domain
Email support@usekaras.com. Changes take effect within a few minutes.