Public beta preview — you're seeing the sneak peek
Squarespace — install the widget
read as.mdOn Squarespace the tag goes into the site-wide Code Injection panel’s Footer field. The tag is the same on every platform — Install the widget has the general picture; this page has the exact place on Squarespace.
The tag
Section titled “The tag”<!-- guuey widget. Add this site to the app's allowed domains or the embed is refused. --><script src="https://widget.guuey.com/v1.js" data-app="app_abc123" async></script>Where it goes
Section titled “Where it goes”- Open the Code Injection panel (Website Tools → Code Injection in your site's dashboard; Squarespace's help center links straight to it).
- Paste the tag into the Footer field — Squarespace injects it "before the closing
</body>tag on every page" — and save.
- Squarespace states code injection is available in the Core, Plus, Advanced, and some legacy billing plans.
- Per-page injection exists too (a page's gear icon → Advanced → Page Header Code Injection), but it targets the header of one page; the widget belongs in the site-wide Footer.
Before it shows
Section titled “Before it shows”Allow your site’s origin (console → Embed → Allowed origins, or guuey apps update <appId> --domains <origin>; about 15 seconds to apply), add the CSP allowances if your site sets a policy, then verify with guuey apps check <appId> --origin <origin> — the steps are on Install the widget.
Give this to your coding agent
Section titled “Give this to your coding agent”Install the Guuey chat widget on this Squarespace site. Before changing anything,read https://docs.guuey.com/embed/squarespace.md and https://docs.guuey.com/install-widget.md(the raw markdown of the two pages) and follow them exactly; do not invent optionsor steps they do not contain.
1. Put this tag in the site-wide Code Injection panel (Website Tools → Code Injection), in the Footer field — injected before </body> on every page, with my app id <appId> in place of app_abc123: <script src="https://widget.guuey.com/v1.js" data-app="app_abc123" async></script> Add nothing else to the tag — except your page's CSP nonce, if the site uses nonces (step 3).2. Tell me the exact origin(s) my pages are served from (scheme + host) so I can add them to the app's allowed domains in the console (Embed → Allowed origins) or with: guuey apps update <appId> --domains <origin>. Remind me that a bare hostname covers the apex and every subdomain, while a scheme-prefixed origin is an exact match, and that changes take about 15 seconds to apply.3. If this site sets a Content-Security-Policy, add exactly these allowances and nothing more. If the policy uses nonces (script-src 'nonce-...'): render the site's per-request nonce on the widget tag the way its other script tags carry it — that is what lets the loader run, and the loader puts the same nonce on the one <style> it injects; then allow https://widget.guuey.com in frame-src and connect-src. If the policy uses host allowlists: add https://widget.guuey.com to script-src, frame-src and connect-src, and 'unsafe-inline' to style-src.4. When I've saved the origin, verify with: guuey apps check <appId> --origin <origin>Stop and ask me before any step those two pages do not describe.