Skip to content

Serving the widget from your own domain

Most sites don’t need this. The usual install snippet loads the widget from app.yamidoo.ai. If you’d rather serve it from your own domain, for example yourdomain.com/yd/, so browser ad blockers leave it alone, you can run a small proxy on your domain that passes every request through to Yamidoo.

The setup has three parts, all on your project’s Installation page under Serve from your own domain (advanced):

  1. Generate a proxy key. It’s shown once, so copy it right away. Only a hash is stored on our side.

  2. Create a Cloudflare Worker with the code from the Installation page. Add the key as a secret named YAMIDOO_PROXY_KEY (Worker → Settings → Variables and Secrets) and add the route yourdomain.com/yd/*.

  3. Swap the embed code for the one on the Installation page. It loads widget.js through your domain and sets data-api, so the chat’s own requests go through your domain too:

    <script src="https://yourdomain.com/yd/widget.js"
    data-site-id="YOUR-SITE-ID"
    data-api="https://yourdomain.com/yd" async></script>

Once visitors come through the proxy, the Installation page shows last request through your proxy with a time, so you can confirm it works.

Behind a proxy, every request reaches Yamidoo from the proxy’s IP address. The widget uses the visitor’s IP for rate limits, bans and location, so without the key all your visitors would share a handful of addresses: one busy visitor could slow down chats for everyone, and banning one spammer would ban them all.

The Worker sends two headers with each request:

Header Value
X-Yamidoo-Proxy-Key Your proxy key (from the Worker secret).
X-Yamidoo-Client-IP The visitor’s IP (Cloudflare’s CF-Connecting-IP).

Yamidoo uses the forwarded IP only when the key matches your project. A request with a missing or wrong key is treated like any other, using the address it came from, so nobody can fake an IP to get around a ban. X-Forwarded-For is accepted in place of X-Yamidoo-Client-IP (its first address is used), but only together with a valid key.

Replacing or removing the key. Replace key issues a new one and the old one stops working within a minute, so update the Worker secret at the same time. Remove turns the feature off; proxied requests then count under the proxy’s own IP.

Other proxies (nginx, Fastly, your own server) work the same way. Forward everything under your path to https://app.yamidoo.ai/ unchanged, including request bodies and streamed responses, and add the two headers.