By default, your chatbot can be embedded on any website. Domain restriction helps limit where your chatbot widget is used. It is an embedding control, not a substitute for authenticating visitors or securing your APIs.
Where to find this setting
From the main ChatLab dashboard, select Chatbots in the main menu, click on the chatbot you want to configure, go to the Settings tab, and select Security in the left sidebar.
How to restrict domains
- In the Allowed domains section, enter your domain names in the text field, separated by commas
- Wait for the automatic save confirmation.
- Reload your website, open the chatbot, and send a test message. Repeat on any other website you need to support; the admin preview alone does not test your website's domain.
For example, if your chatbot should only appear on your main website and your shop, enter:
mydomain.com, shop.mydomain.com
To allow the chatbot on all domains again, clear the field and wait for the automatic save confirmation.
How domain matching works
- Enter lowercase hostnames such as
mydomain.com. The admin form removes common protocol prefixes,www./www2., and trailing paths. - The current implementation checks whether the website origin contains an allowed entry. This is a text match, not an exact hostname match: an entry such as
mydomain.comcan also match its subdomains and other origin strings containing that text. - ChatLab-hosted previews and localhost have exceptions, so test on your actual website.
- Leave the field empty to allow the chatbot on all domains.
Do not use this setting as the sole protection for private data. For server integrations, protect credentials and authorize each request in your own backend.