Skip to content

Identify logged-in shoppers in chat

Tell the chat widget who a logged-in shopper is with Helpdesk.identify, so chats land on the right customer. Learn what verified identity adds.

Last updated 3 min read

On this page

If your store has customer accounts, the chat widget can know who is logged in. Agents then see the chat on the right customer, with their earlier tickets and orders, and the shopper does not have to type their email.

Before you start

  • Who can do this: a developer or anyone who can edit your site's templates.
  • Plan: all plans.
  • What you need: the chat snippet installed, and a template where the logged-in customer's email and name are available.
  • Time: about 10 minutes.

Step by step

  1. Install the chat snippet. See Install live chat on any website.
  2. In the template for logged-in pages, after the snippet, add a small script:
function hd(method, ...args) {
  const h = window.Helpdesk;
  if (h && typeof h[method] === 'function') h[method](...args);
  else (window.Helpdesk = h || { _q: [] })._q.push([method, ...args]);
}
hd('identify', { email: 'shopper@example.com', name: 'Sam Lee', externalId: 'customer-123' });

The small hd helper calls the widget straight away if it has loaded, and otherwise adds the call to the queue the loader replays when it starts.

  1. Fill in the real values from your platform's template variables. Only send externalId if it is your stable customer id.
  2. Load a page as a logged-in test customer, open the chat and send a message.
  3. In the inbox, check that the ticket shows that customer's name and email.

What happens next

The chat ticket is linked to the matching customer in Hushdesk, so agents see their profile, tickets and orders. The pre-chat form is skipped because the visitor is already known.

Verified and unverified

Sent Result
email, name only Unverified. Labels the ticket for your team. It never lets the visitor see someone else's history.
Plus hash = HMAC-SHA256(identity secret, externalId or email) Verified. The identity is trusted because only your server could sign it.

The identify endpoint answers with verified: true or false.

Where to find the secret

Owners and admins see it as Site secret (signs your logged-in users; keep it private), with a copy button. Hushdesk accepts identities signed with it on any site. The WordPress plugin signs logged-in WordPress users for you.

Automatic verification on Shopify. On Shopify, logged-in shoppers will be verified automatically through the app proxy (/apps/helpdesk/me) once the Hushdesk theme app embed is published. Until then, sign the identity on your server with the secret above.

Tips

  • Never compute the hash in the browser. The secret must stay on your server.
  • Use externalId for your platform's customer id. Emails change; ids do not.
  • Use the hd helper so identify works whether your script runs before or after the loader.
  • Sending phone is accepted too, up to 32 characters.

Troubleshooting

"Invalid identity"

The details were not in the expected form, for example an email without an @ or a hash that is not 64 hexadecimal characters. Check the values your template prints.

"Helpdesk.identify is not a function"

Your script ran before the loader, which uses defer. Use the hd helper above, which queues the call until the widget is ready.

The chat is not linked to the shopper

identify did not run on that page, or ran with empty values. Open the browser console and check that it is called with real data.

Verified is always false

Without a hash, every identity is unverified by design. With a hash, check that it is calculated over the externalId when you send one, and over the email otherwise.

Frequently asked questions

How do I pass a logged-in customer's details to Hushdesk chat?

Call identify with the shopper's email and name on pages where they are logged in. Because the loader uses defer, your script may run first, so push the call onto the Helpdesk._q queue when the widget is not ready yet. The loader replays queued calls in order when it starts.

What is the difference between a verified and an unverified identity?

An unverified identity comes from your page alone, so it labels the chat for your team but never opens anyone's earlier conversations to the visitor. A verified identity carries a hash signed with your brand's identity secret, which proves the details came from your server.

How is the identity hash calculated?

It is an HMAC using SHA-256, keyed with your brand's identity secret, over the external id if you send one, otherwise over the email. Send it as 64 hexadecimal characters in the hash field. It must be computed on your server, never in the browser, because the secret must stay private.

Where do I find my identity secret?

Owners and admins find it in Settings, Chat widget, Install, WordPress, under Connect by hand, labelled Site secret, with a copy button. It signs identities on any site, not only WordPress, and agents never see it. If you use the WordPress plugin, it signs logged-in users for you.

Does identifying shoppers skip the pre-chat form?

Yes. When the widget already knows the visitor's name or email, the Before we start form is skipped and the visitor can write straight away. That makes identify the smoother choice for stores with customer accounts, because logged-in shoppers never have to type details your site already has.

Was this helpful?

Still stuck?

Chat with the Hushdesk team. A person answers on every plan.