W Wiretalk Docs
Developer documentation

Domain Restrictions

Control which websites can load your Wiretalk live chat widget with domain allowlists and security settings.

Dashboard: Widget Settings → Allowed domains

Only websites you explicitly allow can load your chat widget. This prevents unauthorized sites from embedding your widget key. Pro

Add your domains

1

Open Allowed domains

Dashboard → Widget Settings → Allowed domains.

2

Add hostnames

Enter bare domains like example.com (covers www.example.com and subdomains) or specific hosts like app.example.com.

3

Include staging & mobile apps

Add staging URLs before testing. For Android/iOS apps, add app:your.bundle.id — see the mobile WebView guide.

Wildcard patterns

Use patterns like *.example.com to allow all subdomains. Wildcards are useful for multi-tenant SaaS apps.

PatternMatches
example.comexample.com, www.example.com, app.example.com
*.example.comAny subdomain of example.com
localhostLocal development on port 80/443
app:com.example.appAndroid, iOS, React Native, or Flutter app with that bundle ID

Mobile app bundle IDs

Android, iOS, React Native, and Flutter apps load Wiretalk in a WebView — not via a website hostname. Register your app using the app: prefix:

app:com.example.app

The widget sends platform and app_id on init instead of a page URL. Both must match an entry on your allowlist. See the mobile WebView guide for setup steps and platform snippets.

Widget blocked?

Common mistake: Forgetting to add both www and bare domain, or missing a staging URL. The widget shows an error: “Add it under Allowed Domains in Widget Settings.”

See Troubleshooting for more fixes.