Identify signed-in users
Tell coview who is signed in with coview('identify'), verify it with a user_hash from your server, and call coview('reset') when they sign out.
Visitors are anonymous until coview learns who they are. When your app tells coview who is signed in, their sessions, chats, calls and tickets come together in one profile, and your team sees a name instead of "Visitor #1234".
Identify a user
Call identify on every page where the person is signed in. Add the one-line queue before the snippet so the call works even before coview has loaded.
coview('identify', {
user_id: 'u_10293', // your own user id
email: '[email protected]',
name: 'Nguyễn Thu Hà',
user_hash: '<user_hash from your server>',
traits: { plan: 'pro' }, // optional attributes
});
| Field | What it is |
|---|---|
user_id | Your own id for the person. Text or a number. |
email, name, phone | Shown on their profile, in the inbox and in Live now. |
user_hash | Proves the identity came from your server. See below. |
traits | Up to 50 attributes. Keys become lowercase letters, digits and underscores (up to 64 characters). Values are text (up to 500 characters), numbers or true/false; null removes a trait. |
Every field is optional, and later calls add to earlier ones. Traits show under Attributes in the inbox's visitor panel.
Visitors who type their email into the chat's pre-chat form are identified that way too.
What identifying changes
- Once coview has an email, phone or user id, the visitor counts as identified: the Identified filters in Sessions and Live now include them, and they appear on the Customers page.
- Until then, coview receives an anonymous visitor's page views straight away, while their other events (clicks, scroll depth, your custom events) wait in their browser, up to 500 events or 30 days. They are sent when the visitor identifies.
- If Only identified visitors is on in Settings › Privacy, recording starts at this point.
Verify identities
Without verification, anyone could call identify from their browser's console with someone else's email. Turn on verification so coview only accepts identities your server signed.
- Open Settings › Install & widget and the Identity tab.
- Copy the Identity secret (it starts with
idv_) into your server's configuration. Never put it in front-end code. - On your server, compute
user_hash: the HMAC-SHA256 of the user id, hex-encoded. When you have no user id, hash the email in lower case instead. The Identity tab has samples for Node, PHP and Python. - Pass the hash to
identifyasuser_hash. - When your pages send it, set Identity verification to Required.
import { createHmac } from 'node:crypto';
// COVIEW_IDENTITY_SECRET lives on your server only
const userHash = createHmac('sha256', process.env.COVIEW_IDENTITY_SECRET)
.update(String(user.id))
.digest('hex');
With verification Required:
- An
identifycall without a validuser_hashis ignored as a whole. - A verified profile opens only with its hash. A browser that was signed in before but sends no hash now carries on as an anonymous visitor, without the profile's name, email or conversations.
- Verified sign-ins merge a person's devices into one profile. Without verification, names and emails are stored, but profiles are never merged.
To change the secret, click Rotate. Hashes made with the old secret stop verifying at once, so update your server straight away.
When the user signs out
coview('reset');
Call reset when the person signs out. coview starts a new anonymous visitor in that browser and keeps nothing of the previous one there: the chat thread and the pre-chat details go too. The next person to use the browser doesn't see the last person's conversations.
A person from coview will help — send us a message, or book a demo and we'll walk through it with you.