Web chat
Put the Fiuit assistant on your site with one line of code, with required contact details and per-channel rules.
Updated:
The web chat is a widget your business pastes into its own site. It talks to the same bot as WhatsApp (same schedules, prices and bookings), with no phone number or third-party approvals. Conversations land in the same Inbox.
If you self-host Fiuit, the web chat ships turned off: enable it with PUBLIC_WEBCHAT_ENABLED=true on the API.
Install step by step
- As the owner, go to Settings → Channels → Web chat.
- Under Allowed sites add each site where you will use it, one per line, with
https://and no wildcards or paths (for examplehttps://www.mystore.com). To test on your computer,http://localhostis accepted. - Choose the main color, button position, default language and an optional title (up to 40 characters).
- Tap Turn on web chat. You get a publishable key
wg_web_…and the code to paste. - Paste the snippet before
</body>on every page where you want the chat:
<script src="https://fiuit.com/widget.js" data-key="wg_web_…" defer></script>
Optional attributes: data-locale (pt, es or en; defaults to the browser language), data-offset-bottom (pixels, to raise the button if your site has a fixed bottom bar) and data-api (API origin, for test environments only).
If you tap Turn off, the chat stops working and open conversations are closed; when you turn it on again you get a new key and must update the code.
There is a demo page at /demo/webchat where you paste the key and see the widget working.
What the visitor sees
- A floating button that opens the chat (full screen on phones, respecting safe areas), in Portuguese, Spanish or English.
- A chat that is short on purpose: brief answers that suggest booking or continuing on WhatsApp. On the web the visitor is anonymous and every answer costs money.
- If the bot asks for their location (for example for a delivery), it offers Use my location, with explicit consent.
- The conversation carries across pages and reloads: when the visitor comes back, the chat shows what was said and any replies that arrived meanwhile (with a new-messages badge if it was closed). A New conversation button, in the chat's ⋯ menu, clears it and starts fresh.
Continuity across pages and reloads
When a conversation opens, the server issues an opaque session code. The widget keeps it in the browser storage (localStorage, or sessionStorage if unavailable) of the site where you installed the chat, with one key per publishable key. It uses no cookies or third-party services, and nothing personal is stored there: no name, phone, email or messages. Declared contact details live only on the server, so the chat does not ask for them again within the same conversation.
- On another page or after a reload, the widget validates the code, loads the history and reconnects to receive new replies.
- Expiry: the conversation expires after inactivity and at a maximum lifetime. If the code expired, was closed or was purged, the widget discards it and starts a new conversation, with no visible error.
- New conversation: the visitor picks it from the ⋯ menu. The code is invalidated on the server, the browser copy is deleted and the chat starts empty. Your team keeps the previous history in the Inbox until it is purged.
- Private mode or blocked storage: the chat still works, but the conversation does not survive a reload.
- Paused channel: if you paused the channel, the chat is not shown even when the visitor has a saved code; when you resume, the conversation continues.
The code is not a strong secret: it is a key to a single conversation, never to others or to the panel. It only works from the origins you authorized in the widget, is subject to the same usage limits, and is invalidated on expiry, on New conversation and when the conversation is purged.
Required contact details
By default the bot does not chat until it has a phone and an email: for any message it replies with a fixed text (no AI) and the chat shows a small form (phone with country selector, in international format, and email). As soon as it is filled in, the visitor's first message is processed on its own, without repeating it.
The details are declared, not verified: they do not identify the visitor and are never merged with existing customers. They are stored encrypted and deleted along with the expired conversation.
Bot rules per channel
Under Channels → Bot rules per channel (owner and manager) you pick the channel (Web chat or WhatsApp) and set:
| Rule | What it does | Web chat (default) | WhatsApp (default) |
|---|---|---|---|
| Required details | Name, phone and/or email before chatting | phone and email | none (the phone already comes from the channel) |
| When it asks | From the first message, after a few replies, or never | from the first message | never |
| Text used to ask | A customizable fixed text | the default | not applicable |
| Reply limit | Cap on bot replies per conversation | 6 | no cap |
| What it offers at the limit | Continue on WhatsApp and/or get the information by email | both | none |
| Bot style in the channel | A tone preference (up to 500 characters) | short answers | none |
These are project rules: the server applies them before invoking the AI, even if someone uses the public API without the widget. At the limit the bot stops replying and stops spending AI, sends a fixed message with the options and the conversation stays in the Inbox as "needs follow-up", with the details the visitor left. If no WhatsApp is connected, that option is not offered.
Security
- The publishable key only opens anonymous conversations: it gives no access to the dashboard, the private API or customer data. You can revoke it at any time.
- The business always comes from the key; the widget never sends a business identifier.
- Only allowed sites can use the chat. No cookies.
- The origin check is not authentication: it only protects against other sites in a browser. Real protection comes from usage limits.
- There are caps on messages per conversation, per hour and per day. When reached, the chat asks the visitor to wait and the AI is not invoked.
- Visitor text is treated as untrusted data, and the widget always renders it as plain text.
- The chat only replies: it sends no proactive messages.
- You can pause the bot or the whole channel if needed; with the channel paused the widget hides.
API
Management (owner): GET|PUT|DELETE /v1/webchat-site. Per-channel rules (owner and manager): GET /v1/bot/channel-policies and PUT /v1/bot/channel-policies/{channel}. The widget's public endpoints are in the OpenAPI contract under /v1/public/webchat.