Category

How to Add Trusted Domains to Your Live Chat Widget

Updated:

Trusted Domains help secure your live chat widget by restricting where it can be embedded or accessed. This ensures only your approved websites can display and interact with the chat service, protecting your brand and customer data.

Why Use Trusted Domains?

  • Display Live Chat only on approved websites.
  • Protect customer chats from unauthorized domains.
  • Restrict chat to specific pages, sections, or subdomains.
  • Prevent the widget from appearing on test or staging sites.
  • Ensure secure widget access with HTTPS and trusted origins.
  • Manage chat availability across multiple company websites.
  • Quickly identify and fix domain-related widget loading issues.

Steps to Configure Trusted Domains

Follow these steps to enable and set up trusted domains for your widget:

  1. Navigate to: Admin > Chat > Live Chat.

    Live Chat.png

  2. Choose an existing widget or click Add Widget.

  3. Navigate to Preference > Security under Chat Bot settings.

  4. Toggle Enable Trusted Domains.

  5. Add a trusted domain in the provided text field.

    Trusted Domain.png

  6. Use appropriate domain patterns:

    Domain Pattern Access Rule
    example.bolddesk.com Exact match (works for both HTTP and HTTPS)
    https://example.bolddesk.com HTTPS-only match
    *.bolddesk.com All subdomains of bolddesk.com
    *.bolddesk.com/sales All subdomains with /sales path
    example.bolddesk.com/sales* URLs starting with /sales (includes subpaths)
    example.bolddesk.com/sales Exact path only (no subpaths)
  7. Click Add Domain to include multiple entries.

    Add Domain.png

After a Trusted Domain is added, the live chat widget will render on that specific domain.
Outside of the specified domain, the live chat widget will not render, and a console error indicating “not found” will be displayed.

Console Error

Required: Update Your CORS Policy

Enabling Trusted Domains is not sufficient on its own. You must also configure your CORS (Cross-Origin Resource Sharing) headers and Referrer-Policy to allow the chat widget to communicate securely across origins.

Refer to this guide to update your CORS settings appropriately: Troubleshooting Guide: Fix Live Chat Widget Loading Issues

Permission for Adding Trusted Domain in Live Chat Widget

To be able to add a trusted domain in the live chat widget, ensure that the Manage Settings permission is enabled in the admin module.

Permission_to_manage_settings_in_BoldDesk.png

Troubleshooting

  1. Live Chat widget does not load on a website

    • Confirm the website domain (and path, if used) matches a Trusted Domain entry exactly according to the configured pattern.
    • If the URL is outside the allowed list, the widget will not render, and a console “not found” error is expected behavior.
  2. Live Chat widget still fails after adding the domain
    Verify CORS and Referrer-Policy are configured as required: Explore Troubleshooting Guide: Fix Live Chat Widget Loading Issues

  3. Cannot add or edit Trusted Domains
    Ensure the admin user role has Manage Settings enabled in the admin module.

Frequently Asked Questions

  1. What happens if I do not add my website domain to Trusted Domains?
    The Live Chat widget will not load on that website, and developer tools show a “not found” console error.

  2. Can I allow all subdomains of a domain?
    Yes. Use a wildcard pattern such as *.example.com.

  3. Does adding https:// change matching behavior?
    Yes. https://example.bolddesk.com enforces an HTTPS-only match.

  4. Do I still need CORS if Trusted Domains are enabled?
    Yes. Trusted Domains control where the widget can render. CORS controls cross-origin communication required for the widget to function.

  5. Can I restrict widget loading to specific paths (for example /help)?
    Yes. Path-based patterns such as example.bolddesk.com/help or example.bolddesk.com/help* allow more granular control.

  6. Can I add multiple allowed domains?
    Yes. Use Add Domain to add multiple Trusted Domain entries.

  7. What is the expected behavior on an untrusted domain?
    The Live Chat widget does not render, and the browser console shows a “not found” error.

Related Articles

  1. Troubleshooting Guide: Fix Live Chat Widget Loading Issues
  2. How to Set Up a Live Chat Widget in BoldDesk
  3. How to Download a Chat Transcript from the Live Chat Widget
  4. How to Customize the Appearance of the BoldDesk Live Chat Widget
Was this article useful?
Like
Dislike
Help us improve this page
Please provide feedback or comments
Comments (0)
Access denied
Access denied
Access denied
Access denied

No articles or sections found
No articles or sections found