For Admins
Channel security
How SupportHub hides channel passwords and tokens, checks incoming webhooks and limits where the widget can be used from.
Passwords and tokens in settings
- Channel fields holding passwords, secrets and tokens (the bot token, IMAP and SMTP passwords and others) reach the interface masked as “••••••••”. The owner and admins see the mask; regular operators don't get these fields at all.
- Saving a channel with the mask or an empty field keeps the stored value. To change a password or token, type the new one.
Checking incoming webhooks
- Telegram: when you connect a bot, SupportHub generates a random secret and hands it to Telegram. Telegram sends it back in the
X-Telegram-Bot-Api-Secret-Tokenheader, and requests without the right secret are ignored. Nothing to set up. - VK: the channel takes the Confirmation string from the community's Callback API settings and a Secret key — any string, which you also enter in VK. With a key set, requests carrying a different key are ignored, so don't leave it empty.
- BILLmanager: the module and the API connection use their own keys — see the BILLmanager integration.
Widget
- Allowed domains in the widget builder (the Privacy section) — one domain per line, without http(s):// or a port; *.example.com allows subdomains. Once the list is filled in, messages from other sites are refused. An empty list lets the widget work on any site.
- To stop a visitor from posing as another customer, pass a signed visitor token to the widget — see HMAC visitor token.
- Request rates are capped per visitor: sending messages at 10 a minute, file uploads and identification at 20 each, ticket replies at 30.
Outgoing requests
- Notification webhooks are signed with HMAC-SHA256 in the
X-SupportHub-Signatureheader — see the notification system. API webhooks have their own signature — see Webhooks. - Requests to Telegram, VK, mail servers and BILLmanager can go through a proxy.
Never share channel tokens and passwords. If a token may have leaked, issue a new one where it was created (BotFather for Telegram, the VK community settings, your mail server for IMAP and SMTP) and save it in the channel.
Was this page helpful?

