Verified and self-declared visitors
A check mark means your app signed the identity. Without one, the name and email were typed in and nobody checked them.
Everyone who writes to you arrives one of two ways, and teem never shows the two alike.
| Verified | Self-declared | |
|---|---|---|
| How they got it | Your app called identify() with a hash signed on your server |
They typed a name and email into the widget, or your app called identify() without a hash |
| In the inbox | A check mark: "Verified by" your organization | No mark |
| On the conversation | "Your app signed this identity when they logged in, so the address is theirs." | "Typed into the widget. Nobody was logged in, so nothing has checked that the address is theirs." |
| In Slack | verified after the email |
self-declared after the email |
| On your public board | A check mark beside their name | Their name only |
| Across browsers | Matched by your user id, so they're the same person everywhere | Tied to the browser they used |
Why it matters
Your organization key sits in your page's source, so anyone can open a console and call identify() with someone else's email. A self-declared message from [email protected] might not be from them. Answer the question, but don't share account details until you know who you're talking to.
Turning on verification
On your server, compute an HMAC-SHA256 of the user's id with your signing secret, and pass it as hash:
hash = HMAC_SHA256(user.id, TEEM_SIGNING_SECRET) # lowercase hex, on the server
teem.identify({ id: user.id, name: user.name, email: user.email, hash: hash })
The signing secret is in Settings → Keys, where only owners can see it. Keep it on your server. The install reference has the details for coding agents.
If the check mark doesn't appear
teem doesn't raise an error for a wrong hash. It saves the visitor as self-declared and carries on, so a broken signature looks the same as a missing one. Check that:
- you sign exactly the
idyou pass toidentify() - the hash is 64 lowercase hex characters
- the secret is current: rotating it in Settings → Keys stops every old signature from verifying