Connectly Webchat is in development
Connectly Webchat is in development
This widget is being rolled out. Interfaces on this page may change before general
availability. The engineering documentation site, which tracks the current build, is at
webchat.connectly.ai/docs.
- An identity key, created once. Connectly keeps only its public half; the private key stays on your server.
- A short-lived identity token your server signs for the logged-in user.
- A function on the page that fetches a fresh token from your server whenever the widget asks for one.
Create an identity key
As an owner of the business, open Settings โ Webchat โ Sign-in in Connectly and select Create key. Connectly shows two values:
A business has one live key at a time. To replace it, revoke it on the same tab, create a new
one, and deploy the new key to your servers. Users cannot sign in between the revoke and the
moment your servers sign with the new key. Like a client key, a new identity key takes up to a
minute to start verifying, and a revoked one stops verifying within a minute.
Sign a token on your server
The token is a JWT signed with RS256 and your private key, with the key id in thekid
header.
Together,
name, email and attributes must fit in 4 KB once encoded as JSON. A token
that breaks any rule is refused, and the chat does not start. It never falls back to an
anonymous visitor.
In Node, with jsonwebtoken:
Hand it to the widget
Give the widget a function that fetches a token. It calls the function each time it starts a session, so the function must fetch a new token every time rather than reuse one.Signing out
When your page logs the user out, tell the widget, so the next person on that browser does not see their conversation:identityTokenProvider.
A signed-in conversation is never written to the browserโs storage: it lives in the page,
and the widget signs the user in again on the next page load.
What happens to the details
- Your inbox shows the tokenโs name and adds its email to the contact. If someone on your team renames the contact, the rename sticks; later tokens do not overwrite it.
- The AI agent sees the name, email and attributes your latest token gave, never an edit made in the inbox. A token without a name keeps the name an earlier token gave.
