The widget is blocked
Six causes: no integrations on your plan, a paused chatbot, a missing token, an unlisted host, an empty allowlist, or a non-HTTPS page.
Browse topics
What it is
The website widget is refused whenever Agentency cannot confirm that the page asking for it is allowed to. That check exists so a leaked embed token cannot be pasted onto somebody else's site and run on your account's credits.
Six things cause a refusal, and they are worth knowing apart because the fixes are unrelated:
- Your plan does not include integrations. The website widget and messaging channels are a paid capability. Your chatbot's public link still works.
- The chatbot is not Active.
- The embed snippet is missing its widget token.
- The page's hostname is not on the chatbot's allowed-domains list.
- The allowed-domains list is empty. In production this denies everything rather than allowing everything — a deliberate default.
- The page is not served over HTTPS. The widget requires a secure page and will not initialise on a plain-HTTP one.
When you would use it
When the bubble never appears on your live site, when the browser console reports a widget failure, or when the chatbot works on its hosted link and not on your website. That last symptom is almost diagnostic on its own.
Where to find it
Dashboard → Chatbots → your chatbot → Integrations → Web. That tab holds both the embed snippet and the allowed-domains list.
Steps
- Check the chatbot is Active on its Playground tab.
- Check your plan includes integrations. Open Settings → Billing as the owner. If it does not, no amount of domain configuration will help — see Integrations and plans.
- Confirm the page is HTTPS. The widget will not start on an insecure page, and this catches people on staging environments.
- View the page source and confirm the embed script is present, complete, and carries its widget token attribute.
- Copy the hostname from the address bar — exactly what is there, not what you think it should be.
- Add it to allowed domains on the Web tab and save. Entries must be bare hostnames like
example.comor*.example.com: nohttps://, no path, no port. The field tells you so if you get it wrong. - Add every hostname you actually serve.
example.comandwww.example.comare different hosts. So is your staging domain. - Reload the page in a private window with the console open.
Reading the browser console
The widget deliberately keeps quiet in the console, because it runs as third-party code inside your customers' pages. Only genuine failures are printed. The ones you will see:
Failed to load chatbot data - widget will not render— the general refusal. It covers the domain check, an inactive chatbot, and a bad token. The specific reason is in the network response, not the console.- A secure-context message — the page is not HTTPS.
- A missing-token message — the embed script has no widget token attribute.
- A cannot-resolve-API-URL message — the snippet was edited and lost its API base URL.
To see the actual reason, open the Network tab, find the failed widget request, and read the response body. That is where Domain not authorized for this chatbot appears.
Domain matching in detail
Matching ignores case, the scheme, the port, and a trailing dot — so those will not trip you up.
What it does not do is guess:
- Subdomains are separate.
example.comdoes not covershop.example.com. Use*.example.comto cover all of them. wwwis a subdomain. If shoppers reach you atwww.example.com, that exact host must be listed or covered by a wildcard.- Localhost does not cover production. A list containing only
localhostdenies your live site. - There is a maximum number of entries. A wildcard is the tidy answer when you have many subdomains.
Rate limits look like a block too
Separately from the domain check, widget traffic is rate-limited per chatbot, per visitor, and per day. When a limit is hit the visitor sees a message asking them to try again later.
You will only meet these with genuinely heavy traffic or with something automated hammering the endpoint. If you see rate-limit responses on a quiet site, look at where your embed token has ended up — that is the signature of a token running somewhere you did not put it. Rotate the situation by tightening the allowed-domains list.
What this is not
It is not a CORS problem you should ask a developer to "turn off". The check happens on Agentency's side, not in the browser's permission model, so disabling anything on your server changes nothing. Add the hostname.
It is not the hosted page's access control. A secret key or password on your chatbot's public link is a completely separate mechanism and has no effect on the widget — see Hosted page access control.
Pausing the chatbot does not help. It makes things strictly worse: a paused chatbot is refused everywhere.
Limits and plan notes
Integrations are a paid capability. The free tier can share the public link but cannot embed the widget or connect messaging apps. That is the most common cause of "the widget just does not work" on a new account.
An empty allowed-domains list denies everything in production. Add at least one host before you launch.
HTTPS is required. No exceptions, including for a test page.
The hosted page has no allowlist. If you need something working in the next ten minutes while you sort the widget out, share the public link — see Share a hosted link.
If nothing here works
Write to support with:
- the chatbot name and the account owner's email,
- the exact URL of the page where the widget should appear,
- the hostnames currently on your allowed-domains list,
- the console message and the failed request's response body from the Network tab,
- confirmation that the chatbot is Active and your plan includes integrations,
- the time of a failed attempt with your timezone.
See Contact Support. Do not paste any API keys.
Common problems
It works on localhost and fails in production.
Add the live hostname. Localhost on the list does not cover your domain.
I allowlisted example.com and shoppers use www.
Different hosts. Add www.example.com, or use *.example.com to cover both.
I use the WordPress plugin and it stopped after a change.
Reconnect the site from the plugin so the host is registered again — see WordPress plugin.
The bubble is not there at all and the console is silent.
That is a different problem — the script is probably not loading. See Widget not showing.
Do I need to list every page of my site?
No. The check is on the hostname only. One entry covers every page on that host.
Common questions
Is this a CORS problem I should ask a developer to disable?
No. The check happens on Agentency's side, not in the browser's permission model, so changing anything on your server has no effect. Add the hostname to the allowed-domains list.
My allowed-domains list is empty. Does that allow everything?
The opposite. In production an empty list denies every site, deliberately. Add at least one hostname before you launch.
Where do I see the real reason for the refusal?
The browser console only prints a general failure, because the widget runs as third-party code on your customers' pages. Open the Network tab and read the failed request's response body.
Does a secret link on my hosted page unblock the widget?
No. Hosted-page access control and the widget's allowed-domains list are entirely separate mechanisms, and neither affects the other.
Do I have to list every page of my site?
No. The check is on the hostname only, so one entry covers every page on that host. But subdomains are separate — use a wildcard if you have several.
Was this article helpful?
Related articles
Allow the widget on your domains
Only listed hostnames may load your widget. An empty list means "not configured", so live sites are blocked.
The widget is not showing
Five gates in order — plan, activation, the snippet, allowed domains, the browser — before you touch your theme.
Embed the website widget
Copy one script tag from Integrations → Web widget, paste it on your published pages, then allow your domain and verify.
Which plans include integrations
Integrations is one switch covering the widget, the plugins, and messaging. Off on Free, on for every paid plan — no partial tiers.
Ready to try it on your own content?
Create a free workspace, add a document, and ask the questions your team is tired of answering.