Skip to Content
Agent ConfigurationSafety and Domains

Safety and Domains

Open Settings -> Security to manage the domain allowlist, visitor rate limit, and human handoff rules.

Domain Allowlist

Add the hostnames where the widget is allowed to call Engine 64. An empty allowlist denies every browser embed.

Examples:

  • example.com
  • support.example.com

Enter hostnames only—no path is required. Allowing example.com also allows its subdomains, such as www.example.com and support.example.com. If you want to test on a separate preview host, add that host explicitly.

Visitor rate limit

Set how many messages one visitor may send in a rolling window, plus the message they see when the limit is reached.

  • Default: 5 messages every 30 seconds
  • Allowed count: 1–100 messages
  • Allowed window: 1–3600 seconds
  • Visitor-facing limit message: up to 240 characters

Engine 64 also applies platform-level protection by IP address and publishable key. Those safeguards are separate from the visitor limit you configure.

Before launch

  • Add the production hostname and any staging host your team genuinely uses.
  • Remove obsolete preview and vendor domains.
  • Test the widget on an allowed host and confirm it fails on an unlisted host.
  • Keep the rate-limit message calm and actionable; do not imply that the visitor has done something wrong.