Limits and spam protection
What already protects the widget from spam and flooding, and what isn’t available yet: slow mode, stop words and slash commands for visitors.
Server-side limits
The server limits how often one visitor can send requests within a project by itself; there’s nothing to set up:
- the first message (a new conversation): 10 per minute;
- messages in a conversation that’s already open: 30 per minute;
- file uploads: 20 per minute;
- passing visitor data (
identify): 20 per minute.
The visitor is recognized by the data-visitor-token token, failing that by the visitor ID from the widget, and failing that by IP. Requests over the limit are rejected (HTTP 429).
Allowed domains
SettingsWidget BuilderPrivacy has an allowed-domains field (security.allowed_origins): one domain per line, without http(s):// or a port:
example.com: only this host;*.example.com: any subdomain, but notexample.comitself; if you need both, add both lines.
Once published, the first message, replies, file uploads and identify are accepted only from pages on these domains (by the Origin or Referer header); others are rejected with 403. An empty list accepts any domain. This protects against someone copying your widget code to another site; a script running outside a browser can fake the header.
Blocking a visitor
If a particular visitor is spamming, an operator can block them in the contact card; see moderation. A blocked visitor can’t start a new conversation from the widget: their message is dropped.

