Skip to main content

Overview

The Weav Chatbot Widget is a lightweight, embeddable chat interface that lets you add AI-powered customer support to any website. It renders a customizable launcher button that opens a chat interface in an iframe, and it can be controlled through a simple JavaScript API.
The configuration options below are to provide developers with more flexibility of the Weav chatbot experience. Most of these features can be controlled within the Weav application for non developers.

Features

  • Fully customizable appearance, including colors, icons, text, position, and theme
  • Mobile responsive with optimized layouts
  • Accessible, including ARIA labels and keyboard support with the Esc key
  • Lightweight with minimal performance impact
  • Secure iframe isolation
  • JavaScript API for initialization, teardown, and event handling

Installation

Basic usage

  1. Include the widget script near the end of your <body> tag.
  2. Call window.WeavWidget.init() once the script has loaded.
The widget automatically injects its mount node and lazy-loads the iframe the first time it opens.

Quick start example


JavaScript API

Once loaded, the script registers a single global object: window.WeavWidget.

Configuration options

Pass configuration through the object supplied to init(). agentSlug is required. All other properties are optional.

Top-level options

Branding options

Use the branding object to customize the launcher button.

Widget options

Use the widget object to customize behavior and appearance.

Widget modes

Button icons

Button positions

Examples

Minimal configuration

Custom branding

Custom icon using an image URL

Left-aligned launcher button

Dark mode widget

Custom widget messages

High z-index for complex sites

Identify logged-in users

Visitors start as anonymous by default. If your site or app has logged-in users, you can tell Weav who they are. Their conversations are then linked to the right customer in Weav, and your team can see who they’re talking to without asking. Your server signs a short-lived token for the logged-in user, and you pass that token to the widget. Weav checks the signature on its servers before it trusts the token.
1

Generate your identity secret

In Weav, go to Agents, open the agent, and select the Chat tab. Under Deploy → Identity verification, click Generate secret, then copy it.Store the secret on your server, for example as the WEAV_WIDGET_IDENTITY_SECRET environment variable. All agents in your workspace use the same secret.
Treat the secret like an API key. Never put it in browser JavaScript, in your page source, or in a public repository.
2

Sign a token on your server

When a user is logged in, create a JWT for them, signed with your secret using HS256.
3

Pass the token to the widget

Render the token into the page and pass it to init() as identityToken.
For logged-out visitors, leave out identityToken. They’ll chat anonymously, just like they do today.

Token claims

string | number
required
Your stable, unique ID for the user, up to 100 characters. Weav matches customers on this value, so it must never change for a user and must never be reused for someone else. Don’t use an email address as the ID.
number
required
When the token expires, as a Unix timestamp in seconds. Keep it short, for example 1 hour. Weav rejects tokens that expire more than 24 hours in the future.
string
The user’s email address. Weav adds it to the customer profile and treats it as verified (see What changes for identified users).
string
The user’s full name, shown on the customer profile.
Only include email if your app has already confirmed that the user owns that address, for example through a verification email or single sign-on. Weav trusts this email to run protected actions, such as looking up orders, without sending the user a verification code.

What changes for identified users

When a visitor has a valid token:
  • Their conversation is linked to a customer. The same user_id always maps to the same customer in your inbox. If no widget-identified customer has that user_id yet, Weav first looks for a customer with the same email and links to them. If none exists, it creates a new customer.
  • They aren’t asked for their email. The lead form is skipped. When the chat is handed to a human, the “leave your email” prompt is skipped too.
  • Protected actions run without a verification code. If the token includes email, integration and custom actions that would normally email the user a one-time code run straight away, using that email. If the token has no email, the user still gets the usual verification code.

Conversation history and switching users

  • Same user returns: their previous conversation resumes.
  • User logs out, or a different user logs in on the same browser: a new conversation starts, so nobody sees someone else’s chat history.
  • Anonymous visitor logs in: a new, identified conversation starts. Their anonymous chat isn’t merged into their account.
  • Single-page apps: when the logged-in user changes without a page reload, call window.WeavWidget.destroy(), then call init() again with the new token, or with no token after logout.

Keep tokens fresh on long-lived pages

Tokens are short-lived, but some pages stay open for hours, like dashboards or single-page apps. To keep visitors identified on those pages, fetch a fresh token from your server before the current one expires, then pass it to setIdentityToken().
  • No interruption: the open chat keeps going and isn’t reloaded. The widget uses the new token the next time the chat window loads, for example when the visitor starts a new conversation.
  • Same signing as before: sign the refreshed token on your server, just like the first one. Never sign tokens in the browser.
  • Logged out on the server: if the user’s session has ended, return null and call setIdentityToken(null). The visitor’s next conversation will be anonymous.
setIdentityToken() keeps the same user signed in. To switch to a different user without a page reload, call destroy() and then init() with the new token, as described above.

Security notes

The widget keeps working, and the visitor chats anonymously. Weav doesn’t show an error to the visitor. This covers missing tokens, expired tokens, tokens with a bad signature, and tokens longer than 4096 characters.
As short as practical. The token is passed to the chat window in its URL, so sign a fresh token on each page load and keep exp short, around 1 hour. If pages stay open longer than that, refresh the token with setIdentityToken() (see Keep tokens fresh on long-lived pages). Weav allows 60 seconds of clock difference between your server and ours.
On the same Identity verification setting, click Regenerate. Tokens signed with the old secret stop working immediately, so update the secret on your server straight away. Until you do, visitors chat anonymously.
No. Anyone who can see the secret can sign a token for any user, so always sign tokens on your server.

Programmatic control

  • Use window.WeavWidget.open() to open the widget without user interaction
  • Use window.WeavWidget.close() to close it programmatically
  • Use window.WeavWidget.destroy() to remove the widget entirely
  • Use window.WeavWidget.init(newOptions) at any time to re-initialize the widget with updated configuration\
Queued open() and close() calls made immediately after init() run as soon as the React tree is ready, so you do not need to wait for a callback.

Events

Use on() and off() to react to widget lifecycle events.
Listeners run inside a guard so thrown errors are logged without breaking other listeners.

Custom mount point

Provide mountElement if you want to render the widget inside your own container.
The widget clears the provided element before rendering. Calling destroy() leaves the element in place so you can reuse it for future mounts.

Triggering the widget from custom elements

You can open the widget and optionally send a pre-filled message from any element on your page. This is useful when you want buttons, links, or other UI elements to start a specific conversation.

Open and send a message by element ID

Open and send a message by class name

Multiple trigger buttons

You can attach different messages to different elements.

Advanced usage

Programmatic control only

The launcher button is visible by default. To hide it and control the widget entirely through JavaScript, set launcherHidden: true and use open() and close().
When launcherHidden is true, the launcher button is completely hidden and the widget can only be opened with window.WeavWidget.open(). This is useful when you want to integrate the widget into your own custom UI.

Re-initializing with new options

Re-initializing ensures updated configuration values are applied cleanly.