Skip to main content
This guide includes features awaiting release. If an option is not available in your workspace, contact StackShift Support.

What you can do

A developer checklist for connecting customer identity, the messenger and notifications. Where to find it: Settings → Installations; your website or mobile application

Before you start

  • A Support installation for the intended brand and environment.
  • The matching web, Flutter, React Native, iOS or Android SDK package. Confirm its distribution/version before adding it; do not guess a package name.

Steps

1
Create the installation and record its public key and allowed website origins. Store the identity-signing secret only in your application backend.
2
For web, initialize createSupport with installationKey, messengerOrigin and apiOrigin from your setup. For mobile, construct the platform client with the API origin and publishable key, then start an anonymous session or identify with a backend-issued assertion.
3
Mount the messenger in the host application. Wire open, close, language and appearance controls as needed; destroy it when its owner is removed.
4
When a signed-in customer changes or signs out, call the SDK identity/logout methods and clear any persisted private session. Native hosts own secure session storage and must persist refreshed credentials and remove cleared ones.
5
If using native push, configure APNs or FCM, register token rotations and restore the correct customer before opening a conversation deep link. Test reception, replies, attachments, sign-out and a notification on the intended device.

Example

Your product’s Help button opens the messenger; signing out removes the previous customer’s private conversation state.

Things to know

  • Web/React use the framework-neutral iframe client; Flutter, React Native, iOS and Android provide native client and conversation UI packages.
  • Native notifications need host provider configuration and permissions. Registering a token does not prove delivery.
  • Drafts are memory-only; do not present them as a durable offline queue.
  • Never ship the identity-signing secret or staff API credentials in website code or a mobile binary.

What happens next

Customers can contact your team from the host application under the correct identity.

If something goes wrong

  • Invalid configuration: check exact origin, public key and environment.
  • Identity fails: check the backend assertion and intended installation; never replace server signing with a browser secret.
  • Push opens the wrong account: restore and authorize the intended customer before navigating.

Add chat to your website

Put a Support chat window on your website and send messages to your team.

Customize the chat window

Match your messenger to the business customers recognize.

Create API credentials, webhooks and custom apps

Connect your own systems with explicit permissions and observable delivery.