Skip to main content
This widget is being rolled out. Interfaces on this page may change before general availability. The engineering documentation site, which tracks the current build, is at webchat.connectly.ai/docs.
If your users log in on your site, you can tell the widget who they are. A signed-in user keeps one conversation on every browser and device, shows up in your inbox under their name and email, and the AI agent uses what you tell it about them instead of asking for it again. It takes three pieces:
  1. An identity key, created once. Connectly keeps only its public half; the private key stays on your server.
  2. A short-lived identity token your server signs for the logged-in user.
  3. A function on the page that fetches a fresh token from your server whenever the widget asks for one.
An anonymous visitor needs none of this. A page that never passes a token gets the anonymous widget described everywhere else in these docs.

Create an identity key

As an owner of the business, open Settings โ†’ Webchat โ†’ Sign-in in Connectly and select Create key. Connectly shows two values: A business has one live key at a time. To replace it, revoke it on the same tab, create a new one, and deploy the new key to your servers. Users cannot sign in between the revoke and the moment your servers sign with the new key. Like a client key, a new identity key takes up to a minute to start verifying, and a revoked one stops verifying within a minute.

Sign a token on your server

The token is a JWT signed with RS256 and your private key, with the key id in the kid header. Together, name, email and attributes must fit in 4 KB once encoded as JSON. A token that breaks any rule is refused, and the chat does not start. It never falls back to an anonymous visitor. In Node, with jsonwebtoken:
In Python, with PyJWT:
Serve it from an endpoint only a logged-in user can reach, and return the token as plain text. The token passes through the userโ€™s browser, where anyone can decode it, so put nothing in it the user should not see.

Hand it to the widget

Give the widget a function that fetches a token. It calls the function each time it starts a session, so the function must fetch a new token every time rather than reuse one.
Set it before the visitor opens the chat. Passing a new function for the same user changes nothing; passing one where there was none is a sign-in, and the widget starts over as that user. The function has 15 seconds to answer, and an error it throws stops the chat from starting rather than signing the user in anonymously. When you revoke the key a user signed in with, their session ends within the hour, and the widget asks your function for a new token.

Signing out

When your page logs the user out, tell the widget, so the next person on that browser does not see their conversation:
In React, stop passing identityTokenProvider. A signed-in conversation is never written to the browserโ€™s storage: it lives in the page, and the widget signs the user in again on the next page load.

What happens to the details

  • Your inbox shows the tokenโ€™s name and adds its email to the contact. If someone on your team renames the contact, the rename sticks; later tokens do not overwrite it.
  • The AI agent sees the name, email and attributes your latest token gave, never an edit made in the inbox. A token without a name keeps the name an earlier token gave.