Appearance
Changelog
0.1.0
The first release.
The widget
- One-line embed (
widget.js), pinned versions with SRI that keep working after upgrades, a plain iframe (/embed/) you can drive withpostMessage, and the@wireface/chatnpm package with React components and hooks. - Four layouts (panel, drawer, a floating face that lets clicks through to the page, inline) and three launchers (bubble, tab, none), with a greeting bubble, unread count, full screen on phones, right-to-left languages and replaceable interface text.
- An animated Wireface face that lip-syncs to voice, mimes text replies, shows moods and follows the pointer; a 2D wireframe face without WebGL2.
- A JavaScript API with events, page tools (with "ask first"), identity, context and consent; window events for tag managers.
- Works under a strict Content-Security-Policy with Trusted Types; the chat window is isolated in an iframe.
The agent
- Text brains: Anthropic (Claude), OpenAI and Google Gemini, with streaming replies, tools, images, refusal fallback on Claude, and long conversations condensed into a summary the model reads first.
- Voice: OpenAI Realtime, Gemini Live, a cascade (speech to text, any brain, text to speech from ElevenLabs, OpenAI or Gemini) and ElevenLabs Agents; barge-in, push-to-talk, and voice and text in one conversation.
- Vision: image uploads, and an opt-in webcam (per turn, continuous or on demand) with
look_at_camera. - Knowledge base from text, files, pages, sitemaps and crawled sites, with citations and a list of unanswered questions.
- Built-in tools, HTTP tools with secrets, MCP servers (Streamable HTTP, SSE, and stdio when allowed), and tools that ask the visitor first.
- Human handoff with opening hours and team presence, leads, thumbs and CSAT ratings.
The server
- One Docker image: the server, admin panel, widget, face engine and these docs; SQLite and files in one data directory.
- Draft and published bot versions, conversations that resume, identity verification across devices.
- Provider keys and secrets encrypted at rest, with master-key rotation; allowed origins, rate limits, daily caps and SSRF protection; an audit log.
- Signed webhooks with retries, a REST API with scoped tokens and an OpenAPI reference, data export and erasure, and retention.