Let's get your site recording
Follow the steps below. We'll auto-detect when your first session arrives.
Your site token is public in the embed snippet — anyone who knows it could try to send data to your account.
Only origins you list under Allowed domains may ingest events. With an empty list, only pages served from this ShieldReplay server (e.g.
/embed-test) can record.
1
Install
2
Domains
3
Verify
4
Automate
1
Install the recording snippet
Paste this into your site's <head> before the closing tag. The agent loads asynchronously and won't block your page.
Loading snippet…
2
Allow your domains
Add every origin where the snippet will run. Requests from any other website are rejected, even if they use your token.
One origin per line, including scheme and port — e.g. https://www.example.com or http://localhost:8080
3
Verify your first event
Open your site in another tab, click around, then come back here. We poll every few seconds automatically.
Waiting for first session…
4
Create your first automation
Turn recordings into actions — alert on rage clicks, route incidents to Slack, or block suspicious patterns.
No automations yet