Fluid signal flow
Last hour of sessions, friction, probes, and incidents — animated replay with event pins at each spike.
Session recordings
Watch replays, spot friction, and jump into live sessions.
Page intelligence
Friction, security signals, and heatmaps per URL.
Incident queue
WAF hits and suspicious activity from the recording agent.
Sessions with probe activity
Open a replay in investigation mode — jumps to the first probe marker.
Configure workspace
Your site
Install the agent, lock down allowed origins, tune recording privacy, and wire user identification — everything your visitors need to be captured safely.
Quick install
Paste this into your site's <head> before any other scripts. Events start flowing within seconds.
Loading snippet…
Token is public in the page source — allowed domains below are what actually protect your data.
Allowed domains
Only these origins may send events and load WAF config. One full URL per line — port matters.
HTTPS sites cannot silently talk to http://localhost — Chrome may show “Access other apps and services on this device” (Local Network Access). That prompt is only for public site → your machine testing; it does not appear for real customers when ShieldReplay is on a public HTTPS host.
Put ShieldReplay behind HTTPS (tunnel/VPS) and use that URL in the install snippet.
www and apex are treated as the same host.
Preview
http://localhost and http://localhost:3000 are different origins. XAMPP on port 80 uses the former.
Privacy & recording
Control sampling, developer timelines, user identification, and what never leaves the browser.
Capture
Users & fidelity
Identify integration
Loading…
Privacy filters
Product analytics
Funnels, retention, and top custom events from the last 30 days.