Identify signed-in users

Tell coview who is signed in with coview('identify'), verify it with a user_hash from your server, and call coview('reset') when they sign out.

Visitors are anonymous until coview learns who they are. When your app tells coview who is signed in, their sessions, chats, calls and tickets come together in one profile, and your team sees a name instead of "Visitor #1234".

Identify a user

Call identify on every page where the person is signed in. Add the one-line queue before the snippet so the call works even before coview has loaded.

coview('identify', {
  user_id: 'u_10293',          // your own user id
  email: '[email protected]',
  name: 'Nguyễn Thu Hà',
  user_hash: '<user_hash from your server>',
  traits: { plan: 'pro' },     // optional attributes
});
FieldWhat it is
user_idYour own id for the person. Text or a number.
email, name, phoneShown on their profile, in the inbox and in Live now.
user_hashProves the identity came from your server. See below.
traitsUp to 50 attributes. Keys become lowercase letters, digits and underscores (up to 64 characters). Values are text (up to 500 characters), numbers or true/false; null removes a trait.

Every field is optional, and later calls add to earlier ones. Traits show under Attributes in the inbox's visitor panel.

Visitors who type their email into the chat's pre-chat form are identified that way too.

What identifying changes

  • Once coview has an email, phone or user id, the visitor counts as identified: the Identified filters in Sessions and Live now include them, and they appear on the Customers page.
  • Until then, coview receives an anonymous visitor's page views straight away, while their other events (clicks, scroll depth, your custom events) wait in their browser, up to 500 events or 30 days. They are sent when the visitor identifies.
  • If Only identified visitors is on in Settings › Privacy, recording starts at this point.

Verify identities

Without verification, anyone could call identify from their browser's console with someone else's email. Turn on verification so coview only accepts identities your server signed.

  1. Open Settings › Install & widget and the Identity tab.
  2. Copy the Identity secret (it starts with idv_) into your server's configuration. Never put it in front-end code.
  3. On your server, compute user_hash: the HMAC-SHA256 of the user id, hex-encoded. When you have no user id, hash the email in lower case instead. The Identity tab has samples for Node, PHP and Python.
  4. Pass the hash to identify as user_hash.
  5. When your pages send it, set Identity verification to Required.
import { createHmac } from 'node:crypto';

// COVIEW_IDENTITY_SECRET lives on your server only
const userHash = createHmac('sha256', process.env.COVIEW_IDENTITY_SECRET)
  .update(String(user.id))
  .digest('hex');

With verification Required:

  • An identify call without a valid user_hash is ignored as a whole.
  • A verified profile opens only with its hash. A browser that was signed in before but sends no hash now carries on as an anonymous visitor, without the profile's name, email or conversations.
  • Verified sign-ins merge a person's devices into one profile. Without verification, names and emails are stored, but profiles are never merged.

To change the secret, click Rotate. Hashes made with the old secret stop verifying at once, so update your server straight away.

When the user signs out

coview('reset');

Call reset when the person signs out. coview starts a new anonymous visitor in that browser and keeps nothing of the previous one there: the chat thread and the pre-chat details go too. The next person to use the browser doesn't see the last person's conversations.

Still stuck?

A person from coview will help — send us a message, or book a demo and we'll walk through it with you.