Articles on: Legal & Security

How to Configure Chatbox Security and Anti-Bot Protection

This article explains how to configure domain security and anti-bot protection for the Crisp chatbox.


Crisp includes security mechanisms to prevent your website chat widget from being used on unauthorized domains and to protect chat sessions from automated traffic, fake visitors, spam, and message floods.


Most anti-bot protection works automatically. From the Chatbox Security settings, you can also control which domains are allowed to use your chatbox and temporarily increase the protection level when your workspace is under attack.


In this guide, you will learn how to:



Understand Crisp chatbox security


Chatbox Security settings are available from Settings → Chatbox Settings → Chatbox Security.



Two types of protection are relevant when securing your Crisp chatbox:


  • Domain protection → controls which websites are allowed to load the chatbox linked to your workspace
  • Anti-bot protection → protects chat sessions and messages against automated abuse and traffic floods


Crisp applies anti-bot safeguards automatically, so you normally do not need to change the protection level.


Manual settings are available when you need to authorize additional domains or temporarily reinforce protection during an attack.


For a broader overview of platform security, read how Crisp manages security across its services.


Lock the chatbox to your website domain


The Lock the chatbox to website domain (and subdomains) option prevents your Crisp chatbox from being loaded from unauthorized domains.


This protects the Crisp Website ID associated with your workspace from being reused on another website.


To enable domain locking:


  1. Open Settings → Chatbox Settings → Chatbox Security
  2. Find General Options
  3. Enable Lock the chatbox to website domain (and subdomains)


When enabled, Crisp checks the domain where the chatbox is loaded against the domains configured for your workspace.


Your configured website and its subdomains can continue loading the chatbox normally.


If your chatbox displays an Invalid Website error after enabling domain locking, read how to troubleshoot "Invalid Website" errors in the Crisp chatbox.


Add additional domains


You can authorize several domains to use the same Crisp workspace while keeping domain locking enabled.


This is useful when the same chatbox needs to be installed on websites such as:



To add another authorized domain:


  1. Open Settings → Workspace Settings
  2. Open your workspace information
  3. Find Additional domains
  4. Add the domain you want to authorize
  5. Save your changes



Once the domain is added, the same Crisp chatbox can load from that website without disabling Lock the chatbox to website domain (and subdomains).


Add each domain where the chatbox is legitimately installed.


Only add domains that you control or explicitly want to authorize for this Crisp workspace.


To install the widget on another website, follow how to install Crisp Live Chat on a custom website.


Understand automatic anti-bot protection


Crisp automatically protects the chatbox against abusive traffic.


These protections can apply when visitors:


  • Create a new chat session
  • Join an existing chat session
  • Send messages through the chatbox


When Crisp detects certain abnormal traffic conditions, additional protections such as Proof-of-Work challenges can be applied automatically before a visitor enters a chat session.


This helps limit automated session creation, fake visitor floods, and message spam without requiring a manual configuration.


In normal conditions, keep the anti-bot protection level on Default (Recommended). Crisp applies the standard protections automatically.


Increase anti-bot protection during an attack


If your chatbox is receiving abnormal bot traffic or spam, you can manually increase its anti-bot protection level.


Go to Settings → Chatbox Settings → Chatbox Security, then find Anti-Bot Protections.



The following levels are available:


Protection level

Behavior

Default (Recommended)

Uses Crisp automatic anti-bot protections

Challenge all users (Easy)

Adds a light verification challenge for chatbox users

Challenge all users (Medium)

Adds a stronger verification challenge

Challenge all users (Hard)

Applies a stricter verification challenge

I'm under attack (Extreme)

Forces the strongest protection for chatbox users


To change the protection level:


  1. Open Anti-bot protection level
  2. Select the level you want to apply
  3. The new protection is automatically saved


The higher the protection level, the more verification may be required before a visitor can enter the chat session or send a message.


This can increase the time required to open or interact with the chatbox.


Use Under Attack mode only when necessary


I'm under attack (Extreme) is the strongest manual protection level.


Use it when your workspace is actively receiving a large amount of automated traffic, fake visitor sessions, or spam messages and the default protections are not sufficient.


To enable it:


  1. Open Settings → Chatbox Settings → Chatbox Security
  2. Find Anti-Bot Protections
  3. Open Anti-bot protection level
  4. Select I'm under attack (Extreme)


Extreme mode forces additional verification for chatbox users. While it is enabled:


  • Opening the chatbox may take longer
  • Sending a message may require additional verification
  • The normal chatbox experience can be temporarily degraded
  • Website visitors may no longer appear normally in MagicMap


Under Attack mode should only be enabled temporarily. Once the abusive traffic has stopped, return the protection level to Default (Recommended).


To restore the default protection, open the same setting and select Default (Recommended).


Crisp will continue applying its automatic anti-bot safeguards after Extreme mode is disabled.


Troubleshooting


Most security-related chatbox issues can be checked from the domain and anti-bot settings.


Issue

What to check

The chatbox takes longer to open or send messages

Check whether a manual Anti-bot protection level is enabled

The chatbox works on the main domain but not another website

Check Additional domains and your domain lock configuration

Legitimate visitors cannot connect to the chatbox

Review the current anti-bot protection level and return to Default if stronger protection is no longer required

Visitors no longer appear normally in MagicMap

Check whether I'm under attack (Extreme) is enabled

The chatbox displays an Invalid Website error

Confirm that the current website is authorized and that the correct Website ID is installed


For domain-related errors, follow the Crisp Invalid Website troubleshooting guide.


For other loading or connection problems, read how to troubleshoot Crisp chatbox visibility issues.

Updated on: 21/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!