You have integrated Intercom, set up trigger messages—but users aren't being identified, events vanish into thin air, and HMAC verification throws a 403 error. This is typical for a shallow Intercom integration. As a result, up to 30% of leads never receive personalized messages, and the support team spends hours manually gathering data.
Over five years, we have integrated Intercom on 50+ projects—from SaaS startups to enterprise solutions with thousands of users. Our stack is PHP 8.3 (Laravel), JavaScript, and Docker. We test each stage on staging to avoid production issues. Let's dive into setting up HMAC, passing custom attributes, and tracking events so the messenger works flawlessly.
How to Set Up HMAC Verification
Generating the HMAC Hash
HMAC (Hash-based Message Authentication Code) protects user data from tampering. Intercom uses your secret key to verify the hash. A 403 error occurs if the key doesn't match or user_id is empty. Obtain your secret key in Intercom settings (Settings > Developer Tools > Identity Verification). Generate the hash server-side:
$userHash = hash_hmac('sha256', (string)$user->id, env('INTERCOM_SECRET_KEY')); Ensure user_id is unique and stable. On one project we saw a 403 error because user_id contained spaces—trim fixed it.
Installing the Script with HMAC
Add the script before </head>. Always pass user_hash:
<script> window.intercomSettings = { api_base: "https://api-iam.intercom.io", app_id: "YOUR_APP_ID", user_id: "<?= $user->id ?>", name: "<?= $user->name ?>", email: "<?= $user->email ?>", created_at: <?= $user->created_at->timestamp ?>, user_hash: "<?= $userHash ?>" }; </script> <script> (function(){var w=window;var ic=w.Intercom;/* snippet */})(); </script> Important: api_base must point to https://api-iam.intercom.io, otherwise it won't work.
How to Pass Custom Attributes
Send user data right after initialization to make the Inbox profile complete. Use the window.Intercom('update', ...) method:
window.Intercom('update', { plan: 'pro', monthly_spend: 150, is_paying: true, last_product_used: 'dashboard' }); Typical mistakes: forgetting to pass attributes after profile updates, or not syncing with CRM. Attributes must be refreshed on every change—otherwise Intercom stores outdated data.
How to Track Events
Every important user action should become an Intercom event. This enables automated triggers:
window.Intercom('trackEvent', 'feature-used', { feature: 'export', format: 'csv', record_count: 1250 }); Events allow behavioral segmentation. For example, if a customer hasn't used a new feature within seven days, send an automated educational message. Intercom supports up to 100 custom events per project.
REST API: Creating Notes and Tasks
Use the REST API for programmatic inbox interactions. For example, adding a note on order placement:
Http::withToken(env('INTERCOM_ACCESS_TOKEN')) ->post('https://api.intercom.io/notes', [ 'user' => ['user_id' => $userId], 'body' => "Placed order #{$orderId} for {$total} RUB" ]); The REST API lets you sync users, add tags, and create tasks.
Why Intercom Is Worth the Investment
Intercom is three times more effective in converting chat to sale thanks to proactive messages and deep product integration. The integration typically pays for itself within two months, reducing support costs by $5,000–$20,000 per year for an average B2B project. At 5,000 users, savings reach $50,000 per year. Comparison:
| Feature | Intercom | Cheap Alternatives |
|---|---|---|
| User identification | HMAC, custom attributes | Only email or ID |
| Events | Custom events + auto-actions | Limited triggers |
| API | Full REST + Messenger | Often weak or missing |
| Knowledge base | Built-in | Absent or paid |
| Analytics | Deep per-user | Basic |
The difference is substantial—especially for B2B with long sales cycles.
How We Deliver Turnkey Integration
We don't just drop in a script. We design the data flow architecture, set up automated messages and tours, and integrate with CRM via REST API.
Work process:
- Analysis: audit current stack, identify integration points (registration, payment event, login).
- Design: attribute schema, HMAC keys, events.
- Implementation: install script, backend code, staging testing.
- Testing: verify identification, events, automated messages.
- Deployment and documentation: hand over access, support instructions.
What's Included
- Messenger setup with HMAC verification.
- Configuration of 5–10 custom attributes (plan, spend, status) and events.
- REST API integration for creating/updating users, adding notes and tags.
- Testing and documentation (all attributes, events, support guide).
- Training the support team on Inbox usage and automated message setup.
Delivery Timeline
| Project complexity | Timeline | Number of events |
|---|---|---|
| Simple (chat only) | 1 day | 0–3 |
| Medium (with attributes) | 2 days | 4–10 |
| Complex (with REST API) | 3 days | 10+ |
Typical Integration Mistakes
- Not passing HMAC hash for logged-in users → 403 error.
- Attributes not updating after profile changes → stale Inbox data.
- Events with identical names overwriting each other → use unique names.
- Not handling user deletion per GDPR → Intercom retains data indefinitely, violating regulations.
Experience: 5+ years, 50+ projects. We guarantee no 403 errors and no lost events. Save up to $50,000 per year on support.
Contact us for a project assessment—we'll prepare your integration in 1–3 days. Order a turnkey Intercom integration from proven engineers.







