Zum Inhalt springen
DeutschlandGPT

Install on your websiteBeta

Paste the embed snippet, allow your domains, and find the right place for it in WordPress, TYPO3, Wix and other systems

This feature is in beta. It is usable, but details can still change.

Two things put a widget on your website: the snippet in your page, and your domain on the widget's allowlist. Miss the second and the browser blocks the chat: the button still appears, but the conversation never loads.

Copy the snippet

Open Install in the builder, or ask the setup assistant for the embed code; it puts the exact snippet for this widget into the chat. Paste it just before the closing </body> tag on every page where the chat button should appear. Usually that means once, in your site's template.

The snippet is a single <script> tag. It is pinned to an exact, frozen loader version with a Subresource Integrity (SRI) hash and crossorigin="anonymous", so the browser checks the script before running it. The loader then opens the chat in an isolated iframe.

Paste the snippet exactly as copied, and never type one from memory. Its widget id and integrity hash are specific to this widget and this loader version. A snippet that looks right but is not fails silently: nothing appears.

Install also offers an inline embed that places the chat inside your page instead of a floating button. See Advanced embedding.

Allow your domains

The domain allowlist is under Security → Allowed domains. List every domain that may show the widget there. The browser enforces this list (through frame-ancestors), so another site cannot fake its way onto it.

  • Only the domains you list may embed the widget.
  • If the list is empty, nobody can embed it. That is fail-secure by design.
  • Changes apply immediately; no publish needed.

How to write an entry

Enter an address with or without https://. Paths are stripped automatically.

EntryEffect
example.comcovers http and https (recommended)
https://example.comhttps only
*.example.comall subdomains, not the domain itself
localhost:3000local testing, with the port, exactly as in the address bar

If your site answers on both example.com and www.example.com, add both.

Local testing and pages without a domain

For a test page on your own computer, serve it over http://localhost:3000 (or whatever port you use) and add localhost:3000 to the list.

An HTML file opened straight from disk (file://) and sandboxed iframes have the origin null, which frame-ancestors cannot express. Test over http://localhost instead. The alternative is Allow null origin under Security, but it removes the domain restriction completely: any website could then embed your widget. Leave it off unless you have to support such pages.

Where the snippet goes in your CMS

Every system has a place for code that belongs on every page, just before </body>. Menu names change between versions and themes; if yours differs, look for "footer code", "custom code" or "body end".

Use a code-snippet plugin that can insert code into the site footer on all pages, or add the snippet to your child theme's footer.php just before </body>. Do not edit the parent theme: the next theme update overwrites it.

If you run a plugin that combines, minifies or delays JavaScript, exclude the widget script from it. Rewriting the script tag breaks the integrity check, and the browser then refuses to run it.

Content Security Policy on your site

If your website sends a Content Security Policy, it has to let the widget in. Allow the DeutschlandGPT address the snippet loads from in script-src (the loader), frame-src (the chat) and connect-src (the configuration request). When connect-src blocks it, Install reports "The page could not reach DeutschlandGPT" for that page.

Check that it works

Open your website in a private browser window and open the chat. If the domain is missing, the chat panel says so in place and names the address to add. The loader also reports every such problem back to DeutschlandGPT, and Install lists the affected pages with the reason and a button to allow the domain in one click. Troubleshooting walks through each case.

Was this page helpful?