BigCommerce data permissions and app lifecycle
Understand what YundaDesk reads, multi-user access, reauthorization, uninstall, and common troubleshooting.
Updated 2026-08-06
A white-label chat bubble for your site
Send and receive through your own system
Bring customer email into one inbox
Connect WhatsApp Business to serve customers
Connect Facebook Pages and handle messages
Receive and reply to Instagram DMs
Connect a LINE Official Account
Connect a Telegram bot for customer messages
Pending — subject to TikTok review and authorization
Connect a Zalo Official Account
Receive and reply to comments
Connect official enterprise customer service accounts
Customer contacts, group chats, and agent collaboration
Select customer service accounts
Each selected account becomes an independent channel that is enabled immediately, with AI replies off by default.
Applies only to this Website Widget channel. The channel name and theme color are channel-specific too.
Enter the title, description, and welcome message in one language. They are translated automatically for each visitor and reused afterward.
Copy the code below and paste it into your website to load the chat widget.
Copy it into your website, bot profile, or integration docs.
Copy<script src="https://cdn.yundadesk.com/widget.js" data-yd-key="yd_widget_main" async></script>- Widget Key
- yd_widget_main
- Script URL
- https://cdn.yundadesk.com/widget.js
- Direct link
- https://cdn.yundadesk.com/?widget_key=yd_widget_main
Telegram bot setup guide
Three steps: ① find @BotFather to create a bot and get the token → ② paste the token on the left → ③ save and enable; the system receives new messages automatically.
1. Create a Telegram bot
- In Telegram, search for @BotFather and open the chat.
- Send /newbot to create a new bot.
- Follow the prompts to set a display name and username (ending in _bot).
- Copy the bot token returned by BotFather.
2. Enter the token on the left and enable
- Paste the token into “Bot Token” on the left.
- Click “Save” at the top, then “Enable”.
- Click “Test connection” to verify the bot token works.
3. Test the bot
- Search for the bot username in Telegram and start a chat.
- Send any message and AI / an agent will reply automatically.
- See Telegram Bot API docs.
The channel credential has expired. Please reauthorize and try again.
Connection failedTelegram bot setup guide
Three steps: ① find @BotFather to create a bot and get the token → ② paste the token on the left → ③ save and enable; the system receives new messages automatically.
1. Create a Telegram bot
- In Telegram, search for @BotFather and open the chat.
- Send /newbot to create a new bot.
- Follow the prompts to set a display name and username (ending in _bot).
- Copy the bot token returned by BotFather.
2. Enter the token on the left and enable
- Paste the token into “Bot Token” on the left.
- Click “Save” at the top, then “Enable”.
- Click “Test connection” to verify the bot token works.
3. Test the bot
Callbacks go through YundaDesk fixed secure egress. If your receiver restricts sources, add the egress IPs to its allowlist.
Callbacks go through YundaDesk fixed secure egress. Allowlist these IPs: 203.0.113.10, 203.0.113.11
View allowlist IPsCustom API setup guide
1. Create a Custom API channel
- Enter the channel name and “your system callback URL” on the left.
- After saving, the system generates a connection key and signing key to confirm message ownership and request authenticity.
- (Optional) Add an IP allowlist to restrict sources.
2. Forward customer messages to YundaDesk
- POST messages as JSON to the webhook URL above.
- Include the connection key, timestamp, signature, and idempotency key in the headers.
- A 200 response means received; other statuses are treated as failures and retried.
3. Receive reply pushes
- Once enabled, YundaDesk pushes agent / AI replies to the “your system callback URL” you entered on the left.
- Deduplicate by external message ID for idempotency.
| Event | Time | Status |
|---|---|---|
| message.created | 2026/07/28 14:20 | Delivered |
| message.created | 2026/07/28 14:06 | Timeout · retrying |
| conversation.assigned | 2026/07/28 13:41 | Signature rejected |
Install one YundaDesk plugin to add live chat, AI support, and a secure Widget binding to a WordPress site.
Use the same YundaDesk WordPress plugin; after WooCommerce is detected and authorized read-only, sync store, customer, order, product, and current cart context.
Connect a BigCommerce store, sync customer order context, and show recent orders in the workspace sidebar.
This WordPress site will be linked to the current workspace, then returned to WordPress Admin to complete the PKCE exchange.
- Site
- https://wp-review.yundadesk.com
- Workspace
- YundaDesk Review
- Versions
- YundaDesk 1.0.0 · WordPress 7.0.2
- WooCommerce
- 10.9.4 detected; read-only store access still requires a separate approval after site connection
This confirmation creates only the site binding and public Widget configuration. It does not read WooCommerce store data. Read-only WooCommerce access must be approved separately in WordPress Admin.
| Customer | Contact | Channel / source | Location | Last interaction |
|---|---|---|---|---|
| MMaria Garcia | Web Widget | 05/18 | ||
| LLukas Schneider | Telegram+49 30 123456 | 05/20 | ||
| AAna Silva | 05/22 |
Check whether AI is safe to serve, what it answers from, and what needs you.
3 outreach tasks open
Look it up using the order number.
Last 3 real matches: Web Widget · Custom API — 1 externally delivered, 2 pending verification, 0 failed.| Category | Capability | Status | Current state | Integration path |
|---|---|---|---|---|
| Proactive outreach | Broadcast noticeCreate a broadcast draft for a channel or all reachable customers. | Draft only | Batch delivery is missing, so AI cannot send directly to every customer. | Connect batch delivery; until then, only confirmed drafts are allowed. |
| Proactive outreach | Private customer messagePrepare or send a follow-up to one specific customer. | Not available yet | This plan does not include the capability yet. | This capability is not available yet and requires no setup now. |
| Proactive outreach | Segment outreachFind customers by conditions and draft outreach for that segment. | Needs setup | Customer segment search is missing, so the target audience cannot be located. | Connect customer segment search to enable this capability. |
| Customer data | Customer profile readRead customer profiles to enrich answers, memory, and outreach decisions. | Available | Read customer profiles to enrich answers, memory, and outreach decisions. | Yuna can use this in learning, answering, and outreach decisions. |
↳Yes, Brazil shipping usually takes 7-12 business days.
Human answered·1↳Auto-detect VIP customers · Detect VIP status and prompt agents to follow up first.
Human answered·1·L2 risk↳Opened items can be returned within 30 days if the package is complete.
Human answered·1↳If DHL has not updated for over 72 hours, check the order first, then hand off for compensation review.
You corrected·1·L2 risk| Skill | Status | Use case | Last 7 days | Actions |
|---|---|---|---|---|
| Order tracking lookupWhen a customer asks where an order is, look it up first, then reply in brand voice. | Active | Lookup | Used 12 times92% success | › |
| Auto-detect VIP customersDetect VIP status and prompt agents to follow up first. | Testing | Triage | Not used yet | › |
When a customer asks where an order is, look it up first, then reply in brand voice.
Choose a customer scenario and run a side-effect-free simulation with the production executor.
Simulation never messages customers or performs real external actions.
Shows real customer-conversation calls only; scenario simulations are excluded.
| Dimension | Conversations | Messages | Avg. first response | Resolved | Share |
|---|---|---|---|---|---|
| Web Widget | 712 | 4,128 | 38s | 496 | 60% |
| Telegram | 284 | 1,620 | 45s | 219 | 24% |
| 198 | 980 | 3m 12s | 146 | 17% |
Profile & project
Agent identity
Basic information
Project identity
Team members
| Member | Role | Status & skills | Last sign-in | Last used | Actions |
|---|---|---|---|---|---|
| ACAnna ChenMeanna@yundadesk.testOnline | Admin | ActiveEnglishRefundsMax 12 concurrent | Today, 09:42 | 2 min ago | |
| LWLeo Wangleo@yundadesk.testOnline | Agent | ActiveEnglishAfter-salesMax 6 concurrent | Yesterday, 18:20 | Today, 10:06 | |
| MGMaria Garciamaria@yundadesk.testOffline | Agent | PendingSpanishPre-salesMax 8 concurrent | — | — |
Notifications
Notification permission
Notification settings
Notification scenes
Test notification
Send testSend a test notification to verify everything works.
Send key
Send-key preference for the conversation input, saved per agent.
Proactive outreach
SaveOutreach policy
Anti-spam and confidence
Human review
Subscription & usage
Upgrade planBuy AI CreditPurchase historyContact opsUsage quotas
Entitlement gate
Write actions are allowed based on workspace status, feature flags and quota usage.
Could not establish a secure connection. If the site is HTTP-only, crawl it again with an http:// URL
| Document | Size | Tags | Updated | Status | Actions |
|---|---|---|---|---|---|
| Support knowledge · Notion · 128 docsSource folder · expand to view synced documents | — | — | Last synced 2026/07/29 03:10 | Retrievable | ⋯ |
| Brazil shipping timelinesCompiled 12 FAQ pairs | — | Updated Jun 3, 2026, 4:00 PM | Searchable | ⋯ | |
| EU customs & duties | — | Updated Jun 4, 2026, 2:30 PM | Indexing | ⋯ | |
| 30-day refund policyCompiled 9 FAQ pairs | — | Updated Jun 2, 2026, 8:00 PM | Searchable | ⋯ |
| Document | Size | Tags | Updated | Status | Actions |
|---|---|---|---|---|---|
| Brazil shipping policy | — | Updated Jun 3, 2026, 4:05 PM | Waiting to index | ⋯ | |
| EU customs & duties | — | Updated Jun 4, 2026, 2:30 PM | Indexing | ⋯ | |
| Brazil shipping timelines | — | Updated Jun 3, 2026, 4:00 PM | Searchable | ⋯ | |
| Import restrictions PDFError: The PDF contains no readable text | — | Updated Jun 7, 2026, 4:30 PM | Indexing failed | ⋯ |
| Document | Size | Tags | Updated | Status | Actions |
|---|---|---|---|---|---|
| tgo.ai · 0 pagesProcessed 3 / Discovered 50 pages | — | — | Crawl job running | Crawling | ⋯ |
| tgo.ai · 47 pagesLast sync succeeded · 47 pages | — | — | Last synced Jun 20, 2026, 4:00 PM | Searchable | ⋯ |
| Customer question | Standard answer | Source | Tags | Status | Actions |
|---|---|---|---|---|---|
| Do you ship to Brazil? | Shipping to Brazil usually takes 7-12 business days. | Compiled · Brazil shipping policy | Enabled | ⋯ |
Connect Notion, choose the pages to sync, and import documents automatically.
Connect NotionNotion is not connected yet
agent confirmationCart recovery is ready to reach 1 customer — confirm the flow.
agent confirmationNew FAQ: track packages from the order page after dispatch.
A customer asked about product materials. Review whether it belongs in the learning base.
A Telegram reply was not delivered. Check channel delivery.
An AI reception run failed. You can inspect the answer trail.
What needs my attention today?
Three things: 2 learning suggestions to review and 1 outreach waiting for your confirmation. Yesterday's auto-resolution hit 84%, up 3 points.
Choose whether built-in or external AI handles automatic replies.
Both visitors and agents will see this name
Selected channels are handled by the current AI. Channels not selected here will not use AI replies.
SelectChoose the AI service that replies across all assigned channels.
Maya Sales Advisor
This is the name of the same default AI agent. Visitors and agents see it; switching built-in or external source does not create a second AI.
AI reception source
Built-in and external AI are mutually exclusive. The selected source replies for the channels assigned below.
Use YundaDesk managed growth with YundaDesk AI learning, skill generation, and review.
External AI only handles auto-replies. It does not participate in YundaDesk AI learning or skill generation.
This connection reads store, customer, order, product, and post-install cart context only. It does not keep addresses, phone numbers, payment details, or full IP data.
YundaDesk keeps BigCommerce store authorization separate from YundaDesk workspace membership and limits store capabilities to read-only support context and its own storefront Widget.
Data YundaDesk reads#
| Object | Purpose | Data boundary |
|---|---|---|
| Store | Identify the conversation source and show basic store information | Store identifier, name, public URL, currency, and similar basics |
| Customer | Match a customer in the Inbox | Platform customer identifier, email, display name, and optional country when available without reading addresses |
| Order | Help agents answer order questions | Order identifier, status, totals, currency, item summary, and timestamps |
| Product and variant | Provide purchased-product context | Product and variant identifiers, name, SKU, price, and availability status |
| Cart and abandoned checkout | Provide cart context created after installation | Cart identifier, status, totals, item summary, and timestamps; no historical backfill |
YundaDesk does not store shipping or billing addresses, phone numbers, payment information, full IP information, or raw BigCommerce responses. Cart context does not store addresses or coupons.
Actions YundaDesk does not perform#
YundaDesk does not:
- edit, cancel, or refund orders;
- modify inventory, products, customers, or discounts;
- change checkout or handle payments;
- invent abandoned-checkout records from historical carts;
- automatically send abandoned-cart marketing messages.
BigCommerce automatically includes its basic store access for every app, so the authorization page may show View and modify basic store information; YundaDesk does not use that default access to change store settings. The only storefront write YundaDesk performs is managing its own Script, and an administrator must still confirm each storefront enable, disable, or repair action in the app.
Events and synchronization#
Store, Customers, Orders, and Products have read-only manual synchronization controls on the app status page. BigCommerce webhooks also keep customer, order, product, inventory, and cart changes current.
Carts and abandoned checkouts begin only after the app is installed and webhooks are healthy. A successful authorization does not prove that every resource already has data. Verify each type with synthetic customers, products, orders, and carts that contain no real personal information.
Multi-user access#
A BigCommerce store can let multiple authorized users open YundaDesk, but BigCommerce identity never bypasses YundaDesk permissions:
- The store owner installs the app and connects the store to one workspace.
- When another BigCommerce user first opens the app, they must sign in in a new tab as an existing YundaDesk member of that workspace.
- A member can perform only the actions allowed by their YundaDesk role.
- Synchronization, webhook repair, storefront changes, and Script repair require permission to manage apps.
Removing a user's YundaDesk app access in BigCommerce ends that user's BigCommerce app session. It does not automatically delete their independent YundaDesk workspace membership. A workspace administrator manages that membership separately when needed.
Reauthorize the app#
If the store token becomes invalid, authorization is revoked, or required permissions change, the app asks for reauthorization and pauses synchronization and storefront status checks.
- Have the BigCommerce store owner open the app.
- Follow the page instructions to reinstall or reauthorize YundaDesk.
- Reopen the app and confirm that both authorization and workspace show Connected.
- Check webhook and storefront Script status. Run a confirmed repair only when the page reports a missing item.
Do not reuse an old account-connection link or forward one to another user.
Disable chat on one storefront#
To stop the Widget on only one storefront:
- Open Apps → My Apps → YundaDesk.
- Find the storefront under Storefront chat.
- Select Disable.
- Use a private browser window to confirm that the storefront no longer loads the Widget.
Other enabled storefronts and read-only store synchronization continue.
Uninstall the app#
Uninstall only when you no longer need the entire store connection:
- In the BigCommerce control panel, open Apps → My Apps.
- Find YundaDesk, open its app actions, and select uninstall.
- Review the BigCommerce confirmation and confirm.
After uninstall, YundaDesk stops synchronization and event processing for the store, ends app sessions, and immediately rejects Widget configuration for its storefronts. BigCommerce cleans up webhooks and auto-uninstall Scripts created by the app. Data created from this store authorization enters cleanup according to the YundaDesk Privacy Policy.
A later reinstall creates a new authorization and requires an explicit YundaDesk workspace selection again. Old connection links and old authorization cannot be reused.
Common troubleshooting#
The Widget does not appear#
- Confirm that the target storefront is Active, not merely that the app is installed.
- Wait one minute, then hard-refresh the public storefront.
- Test the exact HTTPS storefront URL shown in the app.
- Check that the cookie-consent configuration permits functional Scripts.
- Blueprint and unverified headless storefronts are unsupported.
The Script is missing#
YundaDesk never recreates it during a status check. After confirming that an administrator removed the Script, use a member with app-management permission to select Repair Script and confirm.
Webhooks require repair#
Use a member with app-management permission to select Repair webhooks, read the prompt, and confirm. Real-time changes may not reach YundaDesk promptly until repair finishes.
Synchronization has no data#
Confirm that the test store contains visible synthetic customers, orders, and products, then select Sync now for each relevant resource. Carts and abandoned checkouts process new post-install events only and cannot be backfilled by manual synchronization.
If the problem continues, follow Prepare an effective support request and include the public store URL, approximate time, non-sensitive status shown on the page, and reproduction steps. Never send passwords, API keys, customer addresses, phone numbers, or full order records.