Skip to content

Verifying identity with a signed HMAC

Signing the user id on your server so a claim to be somebody can be trusted.

Anything your page sends, a visitor can send too. identify on its own is a claim, not a fact: somebody can open the console and say they are anyone.

Signing it makes the difference.

How it works

Your website has an identity secret, which stays on your server and is never sent to the browser. You sign the user id with it, pass the signature to the widget, and Talkfront checks it.

$hash = hash_hmac('sha256', (string) $user->id, $site->identitySecret);
Talkfront('identify', {
  id: 'usr_1042',
  name: 'Marcus Webb',
  email: 'marcus@webbjoinery.co.uk',
  hash: '…',          // from your server, never computed in the browser
});

The secret is on Settings → Websites → your site. Treat it like a password: if it leaks, signatures stop meaning anything.

What verification buys you

A verified contact is marked as such in the inbox, so an agent can see the difference between “this person says they are Marcus Webb” and “this is Marcus Webb”.

It also protects the history. Unverified details are never merged onto a verified contact, so somebody cannot claim a known customer’s identity and read what that customer asked about before.

Sign the id, not the email

The id is the thing that identifies the account. An email address can change, and in some systems can be set by the user, which would let somebody sign their way into another person’s history.

Getting it wrong quietly

If the signature does not match, the chat still works. The person is simply treated as unverified, the same as if you had not signed at all. That is deliberate, because a broken signature should not stop a customer talking to you, but it does mean a mistake here is invisible until somebody looks.

Check it by opening a chat as a signed-in user and confirming the contact shows as verified.

What goes alongside it

Identify, set and reset covers when to make each call, and passing custom data covers the fields you can send once the person is verified.

Last updated 22 September 2026.