The three keys a plugin asks for
Which key does what, where each one lives, and which of them you can leave blank.
Every Talkfront plugin asks for the same three keys, and they come from the same two screens. This is the long version; each plugin’s own page says where to paste them.
Site key
Settings → Websites → your website. Begins pk_.
This is the one that puts the chat window on your pages. It is public by design: it ends up in the HTML of every page the widget runs on, so treat it as readable by anyone.
What protects you is not the key but the allowed domains list beside it. Add the domain your client area runs on, or the widget is blocked without saying so.
Identity key
The same page, under Identity verification. Begins sk_.
This is what puts the verified tick beside a signed-in customer. The plugin signs their id with it, on your server, and we check the signature.
It must never reach a browser. Anything your page sends, a visitor can send too, so an identity key in a page or a bundle is the same as no verification at all. Verifying identity explains what the signature buys you.
If it has been somewhere it should not, press Generate a new key. Every signature made with the old one stops verifying immediately, so signed-in customers show as unverified until the plugin has the new key.
API key
Settings → API keys, created with the write permission.
This is the only optional one. It is used for syncing customer details (their services, invoices and credit) into your contacts. Chat and identity verification both work without it.
A read-only key is the usual reason a plugin reports that nothing is syncing. Syncing writes, so it needs write.
Syncing is a Pro-plan feature. Leave the API key blank on a smaller plan and everything else still works.
What else to check
Whichever plugin you are installing, two things catch people out and neither is a key:
- The domain of your client area has to be in the website’s allowed domains.
- If your client area sends a
Content-Security-Policy, it needs three sources allowed or the chat button never appears.
Last updated 23 September 2026.