Skip to content
Public beta preview — you're seeing the sneak peek

Plain HTML and static site builders — install the widget

read as .md

On a plain HTML site or a static builder, the tag goes into whatever ends every page. The tag is the same on every platform — Install the widget has the general picture; this page has the exact place on Plain HTML and static site builders.

The tag — put your app id in place of app_abc123
<!-- guuey widget. Add this site to the app's allowed domains or the embed is refused. -->
<script src="https://widget.guuey.com/v1.js" data-app="app_abc123" async></script>
  1. Open the file that ends every page — a shared layout or footer include if your builder has one, otherwise each page's HTML.
  2. Paste the tag just before </body> and save.
  3. Deploy or publish as you normally do; then allow your origin and verify (below).
  • Pasting the tag on one page only shows the launcher on that page — put it in the shared template to cover the whole site.
  • Static builders with a 'custom code' or 'footer code' setting: use its end-of-body / footer slot; that is the same place.

No vendor interface is involved on this platform; nothing to re-verify.

Allow your site’s origin (console → Embed → Allowed origins, or guuey apps update <appId> --domains <origin>; about 15 seconds to apply), add the CSP allowances if your site sets a policy, then verify with guuey apps check <appId> --origin <origin> — the steps are on Install the widget.

Paste into your coding agent
Install the Guuey chat widget on this Plain HTML and static site builders site. Before changing anything,
read https://docs.guuey.com/embed/plain-html.md and https://docs.guuey.com/install-widget.md
(the raw markdown of the two pages) and follow them exactly; do not invent options
or steps they do not contain.
1. Put this tag in the shared layout or footer include every page uses, or each page's HTML if there is no shared template, just before </body>, with my app id <appId> in place of app_abc123:
<script src="https://widget.guuey.com/v1.js" data-app="app_abc123" async></script>
Add nothing else to the tag — except your page's CSP nonce, if the site uses
nonces (step 3).
2. Tell me the exact origin(s) my pages are served from (scheme + host) so I can
add them to the app's allowed domains in the console (Embed → Allowed origins)
or with: guuey apps update <appId> --domains <origin>. Remind me that a bare
hostname covers the apex and every subdomain, while a scheme-prefixed origin is
an exact match, and that changes take about 15 seconds to apply.
3. If this site sets a Content-Security-Policy, add exactly these allowances and
nothing more. If the policy uses nonces (script-src 'nonce-...'): render the
site's per-request nonce on the widget tag the way its other script tags carry
it — that is what lets the loader run, and the loader puts the same nonce on the
one <style> it injects; then allow https://widget.guuey.com in frame-src and
connect-src. If the policy uses host allowlists: add https://widget.guuey.com to
script-src, frame-src and connect-src, and 'unsafe-inline' to style-src.
4. When I've saved the origin, verify with:
guuey apps check <appId> --origin <origin>
Stop and ask me before any step those two pages do not describe.