Widget and embeds

Show your help center only inside your app

Keep your help center off the open web and show it only inside your own website or app, for example behind your product's login. With JS-only access on, your help center loads only inside the widget and embeds on the websites you approve.

Who can do this: Owners and Admins

Turn on JS-only access

  1. In the left menu, click the gear icon, then Settings.

  2. In the General card, under Access & visibility, switch on JS-only access.

  3. Check that Embedding origins, further down the same card, lists every website that shows your widget or your embedded help center. See Choose which websites can show the widget.

  4. Click Save changes.

What changes

  • Anyone who opens your help center's pages directly sees "Help center not available." That includes search engines.

  • The widget keeps working, and so does your embedded help center on the websites in your Embedding origins. On any other website, the browser refuses to show the embed, and following a link from another website to one of your pages shows "Embedding not allowed."

  • Your public MCP server turns off, so readers can't connect AI assistants to your help center. The Public MCP server card in Settings then says "This help center is only available inside the embedded widget (JS-only access)."

To show your full help center inside your app, add the embed code to the page: see Embed your help center in your app on the developer portal. For the widget, see Add the widget to your website.

How it decides who gets in

JS-only access checks where each request comes from, using the address the browser sends along (the referrer). It keeps your help center from being browsed as a normal website, but it isn't access control. To limit who can read your articles, make your help center Private and sign readers in with single sign-on (part of the Catalyst plan). See Control who can see your help center and Sign readers in with your own login (JWT SSO).

Because it relies on the referrer, a page that tells browsers not to send one, with a strict referrer policy such as no-referrer, can't show the embed. Allow at least the origin to be sent.

Turn it off

Switch off JS-only access and click Save changes. Your help center opens at its own address again.

Was this article helpful?

Recent Articles

Articles you view will appear here.

    Comments

    Be the first to comment.

    This is just a preview of the comment. It needs to be approved first in order to appear for everyone.