What you can connect to NexiAgent.
There is no public management API: assistants are configured in the panel, or installed by us. What exists for code is this — and all of it is described in one OpenAPI file.
The public surface
Chat widget
One line of code on your website. The key starts with pk_live_ and is not a secret: what decides who may use the chat is the list of allowed domains in the panel.
Chat API
The endpoint the widget calls. You can call it from your own site without our widget: send the message, receive the reply as a stream (SSE).
Signed webhooks
From the Pro plan, every booking, message, contact and hand-over is sent to an address of yours, signed with HMAC-SHA256.
Platform status
A public JSON feed with the state of every component, for external monitoring.
Start in three steps
- 1Subscribe to the support chat at nexiagent.com/pricing. The widget key appears in the panel the moment the payment clears.
- 2In the panel, allow your website's domain. Without it the widget does not appear — on purpose.
- 3Paste the code below before </body>. For your own integration, call the chat API with the same key.
<script src="https://nexiagent.com/widget.js" data-site="pk_live_…" defer></script>| Method | Path | Notes |
|---|---|---|
| GET | https://nexiagent.com/api/chat/hello?k=pk_live_… | Origin check + appearance · JSON |
| POST | https://nexiagent.com/api/chat | { siteKey, visitorId, message, locale? } → SSE: start · delta · done · error |
| GET | https://status.nexiagent.com/api/status.json | Platform status · JSON |
| POST | https://your-endpoint.example | Webhook · x-nexiagent-event · x-nexiagent-timestamp · x-nexiagent-signature |
Authentication
The chat endpoints carry no secret: they identify the subscription by the public key and accept only requests whose Origin header is on the allowed-domains list. Webhooks are signed with a key only the panel shows. There are no management API keys.
Rate limits
Responses carry RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset. Past the limit the answer is 429 with Retry-After in seconds. Defaults: 30 messages a minute per IP, 60 an hour per conversation, 60 /api/chat/hello loads a minute per IP.
RateLimit-Limit: 30
RateLimit-Remaining: 27
RateLimit-Reset: 42
Retry-After: 42 (429 only)Webhooks
Every delivery is a JSON POST with three headers: x-nexiagent-event, x-nexiagent-timestamp and x-nexiagent-signature (HMAC-SHA256 of “timestamp.body”, hex). Answer 2xx within 10 seconds; otherwise we retry six times over half a day. https only, public addresses only.
{
"event": "booking.created",
"at": "2026-08-07T10:32:11.204Z",
"data": {
"id": "bk_7Kd2",
"kind": "booking",
"channel": "voice",
"contactName": "Ana Silva",
"contactPhone": "+351910000000",
"contactEmail": null,
"scheduledFor": "2026-08-12T15:00:00.000Z",
"notes": "Primeira consulta."
}
}Errors
Every error is JSON with a stable code in “error”, a readable sentence in “message” and, where it helps, “docs” with the documentation address. An unknown path under /api returns a JSON 404, never an HTML page.
{
"error": "origin_not_allowed",
"message": "This page's origin is not on the site's allowed-domains list. Add it in the panel.",
"docs": "https://nexiagent.com/developers",
"origin": "www.example.pt"
}For machines
OpenAPI 3.1
The full description of the public endpoints and the webhooks, with operationIds and schemas.
openapi.jsonllms.txt
What NexiAgent does, when it is the right tool, and where everything is — for agents and language models.
llms.txtMarkdown
Every page on the site answers in Markdown to a request with Accept: text/markdown.
sitemap.xml
Need a connection to your CRM, calendar or invoicing?
We build the connection ourselves, from scratch, to fit your system — no third-party automation services. It is scoped separately, before we start.
Talk to our team