Add the script
Paste one line before your closing body tag. The defer attribute means it never blocks your page render, and the widget mounts after your content is interactive.
<script
src="https://chatbrace.com/widget.js"
data-key="cb_live_YOUR_WIDGET_KEY"
defer
></script>
Restrict it to your domains
The widget key is visible in your page source and always will be — it is a scope, not a secret. Add your domains to the allow-list and everything else is refused. An empty list means any origin, so a typo never locks you out of your own widget.
https://yourdomain.com
https://*.yourdomain.com
http://localhost:3000
Check it is live
Open your site, send one message, then look at the conversation log in your dashboard. If the message is there, you are done.
NoteSeeing nothing? Check the browser console for a 403 — that is almost always the origin allow-list.
Call the API directly
If you would rather build your own interface, the endpoint the widget uses is the endpoint you use. Never send conversation history from the client; the server owns it and anything you send is ignored.
POST /api/widget/chat
Content-Type: application/json
{
"widgetKey": "cb_live_YOUR_WIDGET_KEY",
"conversationId": null,
"message": "Do you ship to Germany?"
}
Rotate a key
One click in the dashboard. The old key stops working immediately, so update your site in the same sitting.