Draft

WebChat on your website

Put the Wagend assistant on your site with a single script line, no WhatsApp number needed.

WebChat is a chat widget your business pastes into its own website. It talks to the same bot as WhatsApp (same schedules, prices and bookings) but needs no phone number or third-party approval: ideal for trying things out and as a storefront on your site.

Install

  1. In the dashboard, as owner, publish WebChat and list the allowed domains (for example https://www.myshop.com). You get a publishable key wg_web_….
  2. Paste the snippet before </body>:
<script src="https://wagend.app/widget.js" data-key="wg_web_…" defer></script>

Optional attributes: data-locale (pt, es or en; defaults to the browser language) and data-api (API origin, for test environments only). Color, position and title come from the workspace configuration.

There is a demo page at /demo/webchat where you paste the key and see the widget running.

What the visitor sees

  • A floating button that opens the chat; texts in Portuguese, Spanish or English.
  • Name and phone are optional and not verified: they do not identify the visitor and are never merged with existing customers.
  • The conversation lives in page memory: reloading starts a new one. Nothing is stored in the browser.

Security

  • The publishable key only opens anonymous conversations: it gives no access to the dashboard, the private API or customer data. It can be revoked at any time (and rotates when you publish again).
  • The workspace always comes from the key; the widget never sends a workspace_id.
  • Only allowed domains can use the chat (per-workspace CORS). No cookies.
  • The Origin check is not authentication. It only protects against other websites in a browser; any non-browser client (a script, curl) can send whatever Origin it likes. That is why the publishable key is not a secret and the real protection is the usage limits, not the origin.
  • Cost caps: messages per conversation and per hour, daily messages per workspace, new conversations per hour and simultaneous live connections. When one is exhausted the API answers 429 with Retry-After and the assistant is not invoked. Idle conversations expire on their own and are purged, including the visitor's declared name.
  • Usage limits per IP, per conversation and per workspace; messages up to 1000 characters.
  • Visitor text is untrusted data for the assistant, and the widget renders all text as plain text (never HTML).
  • The chat is reactive only: it sends no reminders or proactive messages.

API

Management (owner, panel cookie): GET|PUT|DELETE /v1/webchat-site. Public: GET /v1/public/webchat/config, POST /v1/public/webchat/sessions, GET|POST /v1/public/webchat/sessions/{id}/messages and GET /v1/public/webchat/sessions/{id}/events (SSE). The contract lives in packages/openapi/openapi.yaml.

Disabled by default (PUBLIC_WEBCHAT_ENABLED=false) until the security review and explicit activation.