Overview
The Weav Chatbot Widget is a lightweight, embeddable chat interface that lets you add AI-powered customer support to any website. It renders a customizable launcher button that opens a chat interface in an iframe, and it can be controlled through a simple JavaScript API.The configuration options below are to provide developers with more flexibility of the Weav chatbot experience. Most of these features can be controlled within the Weav application for non developers.
Features
- Fully customizable appearance, including colors, icons, text, position, and theme
- Mobile responsive with optimized layouts
- Accessible, including ARIA labels and keyboard support with the
Esckey - Lightweight with minimal performance impact
- Secure iframe isolation
- JavaScript API for initialization, teardown, and event handling
Installation
Basic usage
- Include the widget script near the end of your
<body>tag. - Call
window.WeavWidget.init()once the script has loaded.
Quick start example
JavaScript API
Once loaded, the script registers a single global object:window.WeavWidget.
Configuration options
Pass configuration through the object supplied toinit().
agentSlug is required. All other properties are optional.
Top-level options
Branding options
Use thebranding object to customize the launcher button.
Widget options
Use thewidget object to customize behavior and appearance.
Widget modes
Button icons
Button positions
Examples
Minimal configuration
Custom branding
Custom icon using an image URL
Left-aligned launcher button
Dark mode widget
Custom widget messages
High z-index for complex sites
Identify logged-in users
Visitors start as anonymous by default. If your site or app has logged-in users, you can tell Weav who they are. Their conversations are then linked to the right customer in Weav, and your team can see who they’re talking to without asking. Your server signs a short-lived token for the logged-in user, and you pass that token to the widget. Weav checks the signature on its servers before it trusts the token.1
Generate your identity secret
In Weav, go to Agents, open the agent, and select the Chat tab. Under Deploy → Identity verification, click Generate secret, then copy it.Store the secret on your server, for example as the
WEAV_WIDGET_IDENTITY_SECRET environment variable. All agents in your workspace use the same secret.2
Sign a token on your server
When a user is logged in, create a JWT for them, signed with your secret using
HS256.3
Pass the token to the widget
Render the token into the page and pass it to For logged-out visitors, leave out
init() as identityToken.identityToken. They’ll chat anonymously, just like they do today.Token claims
string | number
required
Your stable, unique ID for the user, up to 100 characters. Weav matches customers on this value, so it must never change for a user and must never be reused for someone else. Don’t use an email address as the ID.
number
required
When the token expires, as a Unix timestamp in seconds. Keep it short, for example 1 hour. Weav rejects tokens that expire more than 24 hours in the future.
string
The user’s email address. Weav adds it to the customer profile and treats it as verified (see What changes for identified users).
string
The user’s full name, shown on the customer profile.
What changes for identified users
When a visitor has a valid token:- Their conversation is linked to a customer. The same
user_idalways maps to the same customer in your inbox. If no widget-identified customer has thatuser_idyet, Weav first looks for a customer with the same email and links to them. If none exists, it creates a new customer. - They aren’t asked for their email. The lead form is skipped. When the chat is handed to a human, the “leave your email” prompt is skipped too.
- Protected actions run without a verification code. If the token includes
email, integration and custom actions that would normally email the user a one-time code run straight away, using that email. If the token has noemail, the user still gets the usual verification code.
Conversation history and switching users
- Same user returns: their previous conversation resumes.
- User logs out, or a different user logs in on the same browser: a new conversation starts, so nobody sees someone else’s chat history.
- Anonymous visitor logs in: a new, identified conversation starts. Their anonymous chat isn’t merged into their account.
- Single-page apps: when the logged-in user changes without a page reload, call
window.WeavWidget.destroy(), then callinit()again with the new token, or with no token after logout.
Keep tokens fresh on long-lived pages
Tokens are short-lived, but some pages stay open for hours, like dashboards or single-page apps. To keep visitors identified on those pages, fetch a fresh token from your server before the current one expires, then pass it tosetIdentityToken().
- No interruption: the open chat keeps going and isn’t reloaded. The widget uses the new token the next time the chat window loads, for example when the visitor starts a new conversation.
- Same signing as before: sign the refreshed token on your server, just like the first one. Never sign tokens in the browser.
- Logged out on the server: if the user’s session has ended, return
nulland callsetIdentityToken(null). The visitor’s next conversation will be anonymous.
setIdentityToken() keeps the same user signed in. To switch to a different user without a page reload, call destroy() and then init() with the new token, as described above.Security notes
What happens if a token is invalid or expired?
What happens if a token is invalid or expired?
The widget keeps working, and the visitor chats anonymously. Weav doesn’t show an error to the visitor. This covers missing tokens, expired tokens, tokens with a bad signature, and tokens longer than 4096 characters.
How long should a token live?
How long should a token live?
As short as practical. The token is passed to the chat window in its URL, so sign a fresh token on each page load and keep
exp short, around 1 hour. If pages stay open longer than that, refresh the token with setIdentityToken() (see Keep tokens fresh on long-lived pages). Weav allows 60 seconds of clock difference between your server and ours.How do I rotate the secret?
How do I rotate the secret?
On the same Identity verification setting, click Regenerate. Tokens signed with the old secret stop working immediately, so update the secret on your server straight away. Until you do, visitors chat anonymously.
Can I create the token in the browser?
Can I create the token in the browser?
No. Anyone who can see the secret can sign a token for any user, so always sign tokens on your server.
Programmatic control
- Use
window.WeavWidget.open()to open the widget without user interaction - Use
window.WeavWidget.close()to close it programmatically - Use
window.WeavWidget.destroy()to remove the widget entirely - Use
window.WeavWidget.init(newOptions)at any time to re-initialize the widget with updated configuration\
open() and close() calls made immediately after init() run as soon as the React tree is ready, so you do not need to wait for a callback.
Events
Useon() and off() to react to widget lifecycle events.
Custom mount point
ProvidemountElement if you want to render the widget inside your own container.
destroy() leaves the element in place so you can reuse it for future mounts.
Triggering the widget from custom elements
You can open the widget and optionally send a pre-filled message from any element on your page. This is useful when you want buttons, links, or other UI elements to start a specific conversation.Open and send a message by element ID
Open and send a message by class name
Multiple trigger buttons
You can attach different messages to different elements.Advanced usage
Programmatic control only
The launcher button is visible by default. To hide it and control the widget entirely through JavaScript, setlauncherHidden: true and use open() and close().
launcherHidden is true, the launcher button is completely hidden and the widget can only be opened with window.WeavWidget.open().
This is useful when you want to integrate the widget into your own custom UI.

