# Choose where your agent can appear

> Limit your intoCHAT agent to your own websites with allowed domains, or make it private, so other sites can't copy your snippet and use your messages.

Your embed code holds only your agent ID, and anyone can read it in your page source. Someone could copy the snippet onto their own site, and every reply the agent gives there would count toward your monthly messages. Allowed domains stop that: you list the websites where the agent may appear, and other websites can no longer show it.

The setting is on the **Share** tab, in the **Where this agent can appear** card at the top.

## Set allowed domains

1. Open your agent and go to the **Share** tab.
2. In **Where this agent can appear**, type your domains under **Allowed domains**, one per line.
3. Click **Save**.

How entries work:

- Enter a domain, such as `example.com`. If you paste a full address such as `https://www.example.com/contact`, only the domain is kept.
- Each domain covers its subdomains. `example.com` also allows `www.example.com` and `shop.example.com`. It doesn't work the other way round: `www.example.com` alone doesn't allow `example.com`.
- `http` or `https` and the port don't matter.
- You can add up to 20 domains.
- An empty list allows any website. That is the default, so agents work as they always have until you add a domain.

If an entry isn't a website address, the card shows "Not a website address" next to it and **Save** stays disabled until you fix it.

> List every address your site runs on, including a staging site or the preview address of your site builder or shop platform. A site that isn't on the list can't show the agent.

## When changes apply

intoCHAT checks the list on every chat request, so a change applies to requests straight away. The chat window itself can take up to a minute to follow a change, because that setting is cached for a short time. If you have just added a domain and the chat doesn't open there yet, wait a minute and reload the page.

The previews on your dashboard and the **Playground** keep working whatever the list contains.

## What other websites see

Once the list has at least one domain, a website that isn't on it gets no chat:

- **Script tag:** the launcher doesn't appear. The browser console shows `intoCHAT: this website is not in the allowed domains of this agent, so the chat is not shown.`
- **Inline iframe:** the browser refuses to load the chat page inside the frame. Most browsers show an empty or error box, and the console mentions `frame-ancestors`.
- **Scripts on that page:** calls to the chat API are refused.

A refused request doesn't use any of your messages.

Your [direct link](/en/docs/iframe-and-link) keeps working, because it opens the chat on intochat.ai rather than on another website. To turn the link off as well, make the agent private.

## Test on your computer

Add `localhost` to the list to test the widget on a local development server, such as `http://localhost:3000`. Any port works. While `localhost` is on the list, the agent also works on other people's local servers, so remove it when you're done testing.

A page opened directly from a file, with an address that starts with `file://`, has no domain. While the list has domains, the chat doesn't appear there. Serve the page from a local server instead.

## Private agents

Switch on **Private agent** and click **Save** when the agent isn't ready for visitors, or when only you should use it.

- Only you can chat with it, in the **Playground**.
- The script tag, the inline iframe and the direct link stop working. The direct link shows "This agent is private." On a site with the script tag, the launcher doesn't appear and the console shows `intoCHAT: this agent is private, so the chat is not shown.`
- Your allowed domains are kept but can't be edited while the agent is private. When you switch **Private agent** off again, the list applies again.

## What allowed domains don't cover

Allowed domains rely on the browser. A browser tells intoCHAT which website a request comes from, and it refuses to show the chat inside a site you haven't listed. That stops other websites from showing your agent or calling the chat API from their pages.

Requests made outside a browser, for example by a script running on a server, don't come from a website, so they can't be judged by domain. They fall under the usual rate limits that apply to every agent instead.

Allowed domains decide where the chat appears, not who can talk to it. Every visitor of your own site can still chat with the agent and read its answers, so only train a public agent on content you are happy to make public.

If the chat doesn't appear where you expect it, see [Troubleshooting](/en/docs/troubleshooting). To install the agent, see [Install with a script tag](/en/docs/script-tag).
