How to enable customer (user) authentication
Last updated October 8, 2026
Overview
Customer authentication makes Atlas verify the identity of every customer who contacts your team through the widget. Without it, anyone who knows a customer's user ID could pass it to Atlas and chat while pretending to be that customer. With authentication turned on, your system sends a unique digital signature (a user hash) alongside each user ID, and Atlas only accepts the identity when the signature matches.
The user hash is created on your server with SHA-256, using the user's ID and your workspace's secret key. You turn authentication on and copy the secret key from App Configuration; your developers then generate the hash in your backend and pass it in the identify call.
This is a global setup: an Admin enables it once for the workspace, and a developer adds the hash to your backend and identify code.
Key Features
- Identity verification: Atlas checks a signature sent with each user ID, so customers cannot be impersonated in chat.
- Server-side signature: The user hash is generated with SHA-256 and your secret key on your backend, never in the browser.
- Secret key management: Reveal, hide and copy the secret key from the Authentication page whenever your developers need it.
- Copy confirmation: Atlas shows a "Copied Secret key to clipboard." notification when the key is copied.
Key terms
| Component | Description |
| User ID | The unique identifier of a customer in your system, passed to Atlas as userId in the identify call. |
| Secret key | A private key for your workspace, shown on the Authentication page. Only your backend should know it. |
| User hash | The signature your server creates by hashing the user ID with the secret key using HMAC SHA-256. It is passed to Atlas as userHash. |
| Identify call | window.Atlas.call("identify", {...}), the call that tells Atlas who the logged-in customer is. |
How to enable customer authentication
Before you start, install Atlas and add the identify call to your app. For instructions, please read: How to install Atlas on your website or app.
- Open the main menu and select "App Configuration" .
- Expand "Getting Started" and select "Authentication". The path is "App Configuration > Getting Started > Authentication" .
- Turn on the authentication toggle to enable verification.
- Click the "Show Password" (eye) icon to reveal your secret key. You can view the key this way at any time.
- Click the eye icon again ("Hide Password") to hide the key once you have checked it.
- Click the "Copy" icon to copy the secret key to your clipboard. Atlas confirms with the notification "Copied Secret key to clipboard."
- Give the key to your developers securely, so they can store it in your backend configuration (for example as an environment variable).
Generate the user hash
In your backend, generate the user hash for the logged-in user with HMAC SHA-256, using the secret key and the user ID. The examples read the secret key from a server-side setting named ATLAS_USER_HASH_KEY; use any name you like. Select your language:
Add the hash to the identify call
- Pass the generated hash to the front end and add it to the identify call as
userHash:window.Atlas.call("identify", { userId: user.id, name: user.name, email: user.email, userHash: user.atlasHash }) - Deploy your changes. Customer conversations are now verified: Atlas chat won't start for anyone trying to spoof a user.
How to view or copy the secret key
- Go to "App Configuration > Getting Started > Authentication" .
- Click the eye icon to reveal the key, or click the "Copy" icon to copy it.
- Click the eye icon again to hide the key.
How to turn off authentication
- Go to "App Configuration > Getting Started > Authentication" .
- Turn off the authentication toggle.
FAQs & Troubleshooting
Why does Atlas not recognize my customers after I enabled authentication?
Common causes:
- The identify call does not include
userHash. - The hash was generated from a different value than the
userIdpassed in the identify call. - The backend uses an old or mistyped secret key. Copy the key again from the Authentication page.
- The hash was not generated with HMAC SHA-256.
Can I generate the user hash in the browser?
No. Generating the hash in the browser would expose your secret key. Always generate it on your server.
Where do I find my secret key?
In "App Configuration > Getting Started > Authentication" . Click the eye icon to view it or the "Copy" icon to copy it.
Who can see the secret key?
Anyone with access to "App Configuration" , which is Admin-only. Share it only with the developers who maintain your backend.
Does this apply to visitors who are not logged in?
Authentication verifies customers you identify with a user ID. It does not apply to anonymous visitors who have not been identified.

