---
title: "Control who can use your web chat"
description: "Password-protect your bot, turn on spam protection, understand where the widget can be embedded and when to allow advanced SDK features."
canonical_url: "https://chatthing.ai/docs/channels/website/access-and-security"
last_updated: "2026-09-25"
---

# Control who can use your web chat

By default, anyone who can reach your bot - through the widget on your site or the bot's link - can chat to it. These settings let you restrict access and cut down on abuse.

**Who can do this:** [team owners and admins](https://chatthing.ai/docs/account/teams#what-each-role-can-do).

All of them are in the web channel settings: open your bot, select the **Channels** tab and click the settings (cog) icon on the **Web** card. Click **Update settings** after any change.

## Require a password

Use a password if the bot has access to information that only certain people should see, such as an internal knowledge bot.

1. In the **Access control** section, turn on **Require a password**.
2. Enter the **Password**.
3. Click **Update settings**.

Visitors are asked for the password before they can start a conversation. This applies to the widget, iframe embeds and the bot's own page. Share the password only with the people who should use the bot.

![The password prompt visitors see on a password-protected bot, with a Password field and Login button](https://res.cloudinary.com/djyjvrw5u/image/upload/v1773424889/docs/web-channel-password-prompt.png)

![The Access control settings with Require a password turned on and a Password field](https://res.cloudinary.com/djyjvrw5u/image/upload/v1773426106/docs/web-channel-settings-password-protection.png)

## Turn on spam protection

If you're getting automated or junk messages through your web chat, turn on **Spam protection** in the **Advanced features** section. It uses Cloudflare Turnstile to check that visitors are human before their messages are accepted.

![The Advanced features section with the Spam protection and Advanced SDK features toggles](https://res.cloudinary.com/djyjvrw5u/image/upload/v1773424895/docs/web-channel-settings-advanced-features.png)

Only turn it on if you're actually seeing spam. It adds a verification step, which can occasionally slow down genuine visitors.

To limit how much a single visitor can use the bot, set a per-user message limit in the bot's [usage limits](https://chatthing.ai/docs/bot-settings/usage-limits).

## Where your bot can be embedded

Chat Thing doesn't restrict which websites can embed your bot. There's no list of allowed domains: the embed code works on any site it's pasted into, and the bot's page works for anyone with the link. If a bot must only be used by certain people, protect it with a password.

## Advanced SDK features

The **Advanced SDK features** toggle in **Advanced features** lets code on the page where the widget is embedded change how the bot behaves: add context, extend or replace its instructions, and register client-side power-ups. It's off by default.

> **Only turn this on for pages you control**
>
> With **Advanced SDK features** on, any script running on a page that embeds your bot can change the bot's instructions. The settings page warns: "Please be aware this could increase the risk of your bot being hijacked." Only turn it on if you need these features and you control every page the bot is embedded on.

What each feature does and how to use it is covered in the [JavaScript SDK](https://chatthing.ai/docs/developers/javascript-sdk) docs.

## How visitors' data is handled

For where conversations are stored, who can see them and how AI providers use your data, see [Security and data](https://chatthing.ai/docs/account/security-and-data).

## Check it works

Open your bot's page (**Open bot**) in a private or incognito window. With a password set, you should see the password prompt before the chat.

## Troubleshooting

### Visitors say they can't send messages after I turned on spam protection

Ask them to reload the page and try again, and check that browser extensions aren't blocking Cloudflare's verification. If it keeps happening and you aren't getting spam, turn **Spam protection** off.

### I want the widget only on my own website

There isn't a domain allow-list. Only paste the embed code into your own sites, and use a password for bots that shouldn't be public.

## Related

- [Security and data handling](https://chatthing.ai/docs/account/security-and-data): Where Chat Thing stores your data, which AI providers process it, whether it's used for training, how access and deletion work, GDPR, DPA and SOC 2.
- [Fix chat widget problems](https://chatthing.ai/docs/channels/website/troubleshooting): What to check when the chat widget doesn't appear, shows old colours, blocks page scrolling or won't load on your website.
