{"Status":true,"Message":"","Response":{"post":{"postuid":"bcd7f423-c5c4-4bcd-8740-6dd4ce0ebd1d","tenantuid":"d8b744fc-2e70-4089-bb80-dd1d08f6c7b2","projectuid":"fc6490ac-7527-4f49-b06e-46f701280e85","title":"Chat Identity Verification","slug":"article/chat-identity-verification","html":"\u003Cp\u003EIdentity verification proves that a signed-in user is who your website says they are. It stops anyone from reading another person\u0027s conversations by putting that person\u0027s user ID in the messenger snippet. Use it whenever you pass \u003Ccode\u003Euser_id\u003C/code\u003E or \u003Ccode\u003Eemail\u003C/code\u003E to the messenger.\u003C/p\u003E\u003Ch2 id=\u0022how_it_works\u0022\u003EHow it works\u003C/h2\u003E\u003Col\u003E\u003Cli\u003EHelpGuides gives your messenger a secret key.\u003C/li\u003E\u003Cli\u003EWhen a user loads your page, your \u003Cb\u003Eserver\u003C/b\u003E signs their user ID with that key and passes the signature to the messenger as \u003Ccode\u003Euser_hash\u003C/code\u003E.\u003C/li\u003E\u003Cli\u003EHelpGuides checks the signature. Only a verified user ID is linked to that user\u0027s past conversations.\u003C/li\u003E\u003C/ol\u003E\u003Cp\u003EWithout a valid \u003Ccode\u003Euser_hash\u003C/code\u003E, the name and email are still shown to your team, marked \u003Cb\u003EUnverified\u003C/b\u003E. They\u0027re never used to look up anyone\u0027s earlier conversations.\u003C/p\u003E\u003Ch2 id=\u0022find_your_secret\u0022\u003EFind your secret\u003C/h2\u003E\u003Cp\u003EGo to \u003Cb\u003EInbox\u003C/b\u003E, then \u003Cb\u003EMessenger settings\u003C/b\u003E, then \u003Cb\u003EIdentity verification\u003C/b\u003E, and click \u003Cb\u003EShow\u003C/b\u003E. Keep this secret on your server. Never put it in browser code.\u003C/p\u003E\u003Ch2 id=\u0022compute_the_user_hash_on_your_server\u0022\u003ECompute the user_hash on your server\u003C/h2\u003E\u003Cp\u003EThe hash is an HMAC-SHA256 of the user\u0027s ID, using your secret, written as lowercase hex. If you don\u0027t pass a user ID, sign the email instead.\u003C/p\u003E\u003Ctable border=\u00221\u0022 style=\u0022border-collapse: collapse; width: 100%;\u0022\u003E\u003Cthead\u003E\u003Ctr\u003E\u003Cth\u003ELanguage\u003C/th\u003E\u003Cth\u003ECode\u003C/th\u003E\u003C/tr\u003E\u003C/thead\u003E\u003Ctr\u003E\u003Ctd\u003ENode.js\u003C/td\u003E\u003Ctd\u003E\u003Ccode\u003Ecrypto.createHmac(\u0027sha256\u0027, SECRET).update(user.id).digest(\u0027hex\u0027)\u003C/code\u003E\u003C/td\u003E\u003C/tr\u003E\u003Ctr\u003E\u003Ctd\u003EC#\u003C/td\u003E\u003Ctd\u003E\u003Ccode\u003EConvert.ToHexString(new HMACSHA256(Encoding.UTF8.GetBytes(SECRET)).ComputeHash(Encoding.UTF8.GetBytes(user.Id))).ToLowerInvariant()\u003C/code\u003E\u003C/td\u003E\u003C/tr\u003E\u003Ctr\u003E\u003Ctd\u003EPHP\u003C/td\u003E\u003Ctd\u003E\u003Ccode\u003Ehash_hmac(\u0027sha256\u0027, $user-\u0026gt;id, $SECRET)\u003C/code\u003E\u003C/td\u003E\u003C/tr\u003E\u003Ctr\u003E\u003Ctd\u003EPython\u003C/td\u003E\u003Ctd\u003E\u003Ccode\u003Ehmac.new(SECRET.encode(), user.id.encode(), hashlib.sha256).hexdigest()\u003C/code\u003E\u003C/td\u003E\u003C/tr\u003E\u003C/table\u003E\u003Cp\u003EThen pass it in the snippet alongside the user\u0027s details:\u003C/p\u003E\u003Ccode\u003Ewindow.HelpGuidesChatSettings = {\n  app_id: \u0022YOUR_APP_ID\u0022,\n  user_id: \u002212345\u0022,\n  email: \u0022jane@example.com\u0022,\n  name: \u0022Jane Doe\u0022,\n  user_hash: \u0022HASH_FROM_YOUR_SERVER\u0022\n};\u003C/code\u003E\u003Ch2 id=\u0022require_verification\u0022\u003ERequire verification\u003C/h2\u003E\u003Cp\u003EOnce every page that passes user details also passes a \u003Ccode\u003Euser_hash\u003C/code\u003E, switch on \u003Cb\u003ERequire verification\u003C/b\u003E. The messenger then refuses any user ID or email without a valid hash.\u003C/p\u003E\u003Ch2 id=\u0022rotating_the_secret\u0022\u003ERotating the secret\u003C/h2\u003E\u003Cp\u003EClick \u003Cb\u003ERotate\u003C/b\u003E to create a new secret. Every hash made with the old secret stops working immediately, so update your server at the same time.\u003C/p\u003E\u003Ch2 id=\u0022visitors_who_sign_in_partway_through\u0022\u003EVisitors who sign in partway through\u003C/h2\u003E\u003Cp\u003EIf someone chats anonymously and then signs in, their earlier conversations move to their verified account automatically. Call \u003Ccode\u003EHelpGuidesChat(\u0027shutdown\u0027)\u003C/code\u003E when a user signs out. Otherwise the next person on that browser could see their conversations.\u003C/p\u003E\u003Cp\u003ESee also \u003Ca href=\u0022/article/installing-the-chat-messenger-on-your-website\u0022\u003EInstalling the Chat Messenger on Your Website\u003C/a\u003E and \u003Ca href=\u0022/article/chat-messenger-javascript-api\u0022\u003EChat Messenger JavaScript API\u003C/a\u003E.\u003C/p\u003E","publish_status":0,"post_type":"Article","author":{},"featured_image_updating":false,"meta_description":"Secure user identity in your chat messenger using user_hash verification to protect conversations and control access via server-side HMAC-SHA256 signatures.","display_toc":true,"has_workingcopy":false,"allow_indexing":true,"total_views":0,"date_published":"2026-09-26T16:45:09.15","date_updated":"2026-09-26T16:45:09.82","date_created":"2026-09-26T16:28:48.633"}}}