PepoChat

Visitor email verification

How a visitor proves an email address with a one-time code, and which features it unlocks.

Chats start anonymous. A visitor who wants the agent to use anything personal can prove an email address with a one-time code sent to that inbox. Verification is never forced; the agent can suggest it when it would help.

How a visitor verifies

  1. Tap the shield icon in the chat header

    The icon reads "Verify your email". It opens a screen titled Confirm it's you.

  2. Enter the email and request a code

    The visitor types the address and taps Email me a code. We send a message with a six-digit code and the subject "<code> is your verification code".

  3. Enter the code

    The visitor types the code and taps Verify. On success the screen reads Your email is verified and the shield turns green with the title "Email verified".

The rules

  • Codes are six digits and expire after 10 minutes.
  • A code allows 5 attempts. After that the visitor requests a new one.
  • Resend code has a 60-second cooldown.
  • Codes are stored only as a hash tied to the visitor's session, and the email is attached to the session only once the code is confirmed.
  • Verification belongs to the session, which lasts 24 hours. A returning visitor verifies again in a new session.

Visitors who type a wrong or expired code see plain messages such as "That code is incorrect. Please try again." or "That code has expired. Request a new one."

What verification unlocks

FeatureWithout verificationWith verification
Meeting memoryNever shownThe agent may recall this person's past meetings with your team
Appointment bookingThe agent asks for a name and emailBooked with the verified email and name automatically
Shield icon in the chat headerGrey, "Verify your email"Green, "Email verified"

Integration actions such as looking up an order or a subscription by email are not gated by verification; the agent collects the email in the conversation like any other input. If your workflow needs proof of identity before such lookups, tell the agent so in the action's "when to use" description, or ask your visitors to verify first.

For your team

A verified email is visible on the conversation in the team inbox, so a colleague who takes over knows who they are talking to.

Something missing or wrong on this page? Tell us and we will fix it.