The site script (opa.js)

Last updated 7 Oct 2026

The script sends your site's forms to the panel from the visitor's browser. It works on any site: WordPress, Shopify, Wix, static pages or your own code.

Install

In the panel, open the site, tab Script, turn it on, choose what it collects and copy the line into every page (before </body> or in the <head>):

<script src="https://ingest.onepanelforall.com/opa.js" data-key="opp_…" async></script>

The key opp_… is public. What protects it: the panel answers only requests coming from the site's own domain (https://example.com, https://www.example.com) and from the extra addresses you add in the panel.

Mark your forms

Add data-opa to a form to tell the script what it is:

<form data-opa="contact">…</form>  <!-- a contact message -->
<form data-opa="signup">…</form>   <!-- a new user or newsletter subscription -->
<form data-opa="order">…</form>    <!-- an order -->

With Recognise forms automatically turned on in the panel, unmarked forms are recognised by their fields (an email and a message field make a contact form, for example).

What is never read

Password fields, card fields (autocomplete="cc-…", names like card, cvv), hidden fields, file fields and fields marked data-opa-ignore. Forms that contain a password field are never recognised automatically.

Custom events

<script>
  window.opa = window.opa || { q: [] };
  opa.q.push(['track', 'booking_requested', { service: 'consultation', people: 2 }]);
</script>

Up to 20 properties per event; values are text, numbers or true/false.

Limits

30 requests per minute per visitor and the monthly event limit of your plan. Kinds you turned off in the panel are ignored.