Skip to content

Allowed domains, and why the widget won't load without them

The list that decides where your chat window is allowed to appear, and the four entries people forget.

Every website in Talkfront has a list of domains. The widget loads on those and refuses everywhere else.

Why it exists

Your site key is public, because it ships in your HTML. On its own that is fine: a key cannot read your conversations. But without a domain list, anyone who copied it could put your chat window on their own site, and the people typing into it would believe they were talking to you.

The domain list is what makes the public key safe. It is not a formality.

Setting it

Settings → Websites → your site, under Allowed domains. Add one per line.

  • example.com also covers www.example.com.
  • *.example.com covers every subdomain.
  • Add localhost if you want the widget while developing.

The four people forget

Almost every “the widget isn’t showing” turns out to be one of these:

  1. The other one of www and non-www, if your site answers on both.
  2. Your staging or preview domain. Vercel, Netlify and friends give every branch its own hostname; the widget will not load on any of them unless they are listed or covered by a wildcard.
  3. A checkout or account subdomain, which is often a different host from the main site and is exactly where people have questions.
  4. localhost, which is why it works in production and not on your machine.

What it looks like when it is wrong

Nothing. The launcher simply does not appear, and the page is otherwise fine. There is no error on the page, because a visitor should not be shown your configuration problems.

Open the browser console and you will see the request refused. That is the fastest confirmation, and it is the first thing to check before looking at anything else.

It is not the same as the frame policy

The chat window is also protected by a frame-ancestors policy built from this same list, which stops the frame being embedded on a site you have not approved. You do not configure that separately; keeping the domain list right keeps both right.

Last updated 22 September 2026.