All install guides

Last updated:

Add Sincra to Squarespace

To add Sincra to a Squarespace site, paste your Sincra code into the Footer field of the Code Injection panel and save. Squarespace adds it before the closing </body> tag on every page of your site.

What do I need before I start?

  • A Sincra account with an active plan. Before you choose a plan, you can try the assistant in the Simulator of your dashboard.
  • A Squarespace plan with code injection. Squarespace offers it on the Core, Plus and Advanced plans, and on some legacy plans.

Step 1: Get your code from Sincra

In your Sincra dashboard, open the Widget page and add your domain under Allowed domains, for example example.com. Then click Copy in the Installation card. The HTML guide explains both steps in more detail.

Step 2: Open the Code Injection panel

In your Squarespace site, open the Pages panel, then Website Tools, then Code Injection.

Step 3: Paste the code in the Footer field

  1. Paste your Sincra code in the Footer field.
  2. Click Save.

Step 4: Check that it works

  1. Open your website in a private browser window. Squarespace may turn off custom scripts while you edit your site, and a private window shows the site as your visitors see it.
  2. Open the chat and ask a question that your pages answer.

Good to know

  • Squarespace checkout pages don't support custom code, so the assistant doesn't appear on checkout.
  • If Squarespace asks you to disable scripts while you edit, it only affects the editor preview, not your visitors.

Why doesn't the assistant appear?

  • Your domain is not in Allowed domains, or it is written differently from the address of your site.
  • Your plan is not active yet.
  • The code was pasted in the Header field or in a page's settings instead of the site-wide Footer field.

Does my site's Content Security Policy need changes?

Most websites don't have a Content Security Policy, and then there is nothing to change. If yours sends one, it must allow Sincra, or the assistant won't load or won't answer. Add these sources to your policy:

script-src https://sincra.cloud
connect-src https://sincra.cloud https://sincra-prod-app-gr535u4h4q-no.a.run.app
frame-src https://sincra.cloud
style-src 'unsafe-inline'

If your policy doesn't list one of these directives, browsers fall back to default-src (for frame-src, to child-src first if you have it), so add the sources there. If your style-src uses a nonce or a hash, browsers ignore 'unsafe-inline': in that case, write to support@sincra.cloud.

What each line is for: the assistant's script loads from sincra.cloud, it talks to our servers at the two addresses in connect-src, its bot check runs in a small frame from sincra.cloud, and it styles itself with an inline style block. It loads no images, fonts or other scripts on your pages.

What if the code is on the page twice?

Keep one Sincra code on each page. If you paste a new code, remove the old one first: two codes on the same page don't work correctly.

Sources

Steps checked on September 30, 2026 against the Squarespace Help Center guide Customize parts of your site with code injection.