Add the script to any website
The snippet works on any website: a hosted shop platform, WordPress and WooCommerce, PrestaShop, or your own code. Using Next.js? See the Next.js guide.
Paste the snippet
Section titled “Paste the snippet”Copy the snippet from Install & setup in Quomerce, so your key is already in it. Paste it into the <head> of every page, as high as you can:
<script>!function(w,d,u){if(w.qm&&w.qm.s)return;var q=w.qm=w.qm||function(){(q.q=q.q||[]).push(arguments)};q.q=q.q||[];q.s=u;var e=d.createElement("script");e.async=!0;e.src=u;(d.head||d.documentElement).appendChild(e)}(window,document,"https://ingest-prod.quomerce.com/sdk/v0/qm.js");qm("init",{key:"pk_live_…"});</script>What it does:
- It defines
window.qmright away. Every call made before the script has loaded is queued, then run in order once it has. So you can callqm(...)anywhere, at any time. - It loads
https://ingest-prod.quomerce.com/sdk/v0/qm.jsasynchronously. It never blocks the page from rendering. - A second copy of the snippet on the same page does nothing. Still, put it in one place only, such as your theme’s header template.
v0 always serves the newest compatible version of the script. You never need to update the snippet when the script changes.
init options
Section titled “init options”qm("init", { key: "pk_live_…", // required: the site's public key commerce: "auto", // "auto" (default) or "manual", see "Commerce: auto or manual" cookieDomain: ".example.com", // share one session across subdomains debug: false, // true: log what the script does to the console});| Option | Default | Meaning |
|---|---|---|
key |
— | The site’s public key, pk_live_…. Required. |
commerce |
"auto" |
Where commerce events come from. See Commerce: auto or manual. |
cookieDomain |
The current host | Set it to .example.com if visitors move between example.com and shop.example.com, so it stays one session. |
debug |
false |
Writes what the script did, and what it ignored, to console.debug. The script logs nothing otherwise. |
endpoint |
The script’s own host | Where events are sent. You never need it in production. |
Call init once per page. The snippet already does it.
Content Security Policy
Section titled “Content Security Policy”If your shop sends a Content-Security-Policy header, allow the Quomerce host:
script-src ... https://ingest-prod.quomerce.com;connect-src ... https://ingest-prod.quomerce.com;The inline snippet also needs your CSP nonce on its <script> tag, or 'unsafe-inline' in script-src.
The script loads its other parts (replay, web vitals, commerce detection) from the same host, so these two lines cover them all.