The selected active agent controls the tools exposed by both audiences, including configured toolkits, MCP tools, scripts, skills and subagents. Runtime settings are read from the agent configuration for each turn. Configure a dedicated agent for each public purpose and publish it explicitly. Visitors cannot override the agent, model, tool grants or organization.
Public sessions run tools with the publishing member’s current organization authorization. Disabling the agent or removing that member’s assistant access prevents execution. Visitors can answer matching interactive tools; organization write approvals require an authenticated member.
Preview and publish
Open Agents → Storefront in your organization. Select Create storefront chat, choose an active agent, enter the exact websites allowed to embed it, and customize its design. Storefront manages public visitor chats and is included in Enterprise. This requirement applies to every public visitor installation, including React application layouts. Public sessions and subsequent requests stop if the organization loses this entitlement. Authenticated (org_member) application chat is available on every plan, subject to organization membership and assistant permissions. Building and publishing applications with the OmniCommerce Applications feature requires Enterprise separately.
The editor has Settings, Design, and Embed code tabs with a persistent design preview. In Design → Chat window, choose a floating window or a full-height sidebar. In Embed code → Install in, choose a website chat bubble, inline website chat, or React application. All three installations support public visitors. Code updates immediately as you customize; publishing activates the deployment ID already shown in the draft snippet. Live preview opens /sdk/chat-preview with your deployment and layout selected. Design previews do not start AI conversations. Each chat has its own design, agent and allowed origins.
The listing supports live search, a searchable status filter, and individual or full resets. Filters stay in the URL so views can be bookmarked and shared. On mobile, use Filters to reveal advanced controls.
For other websites, publish using the authenticated management endpoint from an organization member session:
DELETE /api/embed/deployments using { deploymentId, organizationId } in the same authenticated management session. Disabling prevents new sessions and subsequent chat requests.
React applications
Install the released SDK with its optional React integration:/sdk/embed.global.js and an installable SDK build at /sdk/omni-commerce-sdk.tgz.
baseUrl="http://localhost:3000" to use a local OmniCommerce host.
Use separate providers for separate assistants:
Application context and UI actions
SDK 0.8.0 can connect the selected agent to your app’s live state and local UI actions. Passapplication with a name, description, and getContext() snapshot, plus optional frontendTools. The same options work on OmniProvider, createOmniChatEmbed, and createOmniChatWidget, including public deployments.
getContext() runs before each turn, so React state and filters stay current without recreating the chat. Share only selected data; never return credentials, entire application stores, or base64 images. Context is limited to 32 KiB of JSON and the complete configuration to 64 KiB.
Frontend tools must use unique app_ names, JSON object schemas, and bounded array arguments for actions that can target several controls or entities. Up to 24 tools are supported. Native LangGraph interrupts park these calls while the SDK runs your execute() function locally. The host result returns as the tool result, including failures. Keep results under 12,000 bytes, return concrete evidence, and make mutations idempotent; execute() receives toolCallId and an abortSignal that cancels when the embed is destroyed. Repeated delivery of the same parked call is deduplicated during that embed’s lifetime.
Local UI tools do not add server permissions or override existing tools. The deployment’s agent continues to control its server tools, scripts, MCP servers, skills, and subagents. The SDK validates frame source, exact origin, deployment, and request IDs before calling a host handler. Functions remain in your application and are never sent to the model. Custom React tool renderers are not exposed through the hosted iframe.
Try /sdk/chat-preview?deploymentId=YOUR_DEPLOYMENT_ID&view=application to see the agent change the preview’s Activity view and search control.
JavaScript websites
createOmniChatWidget(document.body, options) instead. It accepts presentation (floating by default or sidebar), launcherLabel, position (left or right), launcherBackground, launcherForeground, panelBackground, and panelForeground, and returns open(), close(), and destroy(). SDK 0.8.1 loads the saved launcher label, layout, position and colors from your deployment ID before showing the bubble. The generated Storefront snippet contains only deploymentId and baseUrl, so saved design and agent changes apply on the next website load without editing the snippet or redeploying your website. Explicit styling options remain available for hosts that intentionally want overrides; omit them to inherit future saved changes. Replace older snippets that contain styling options once with the new deployment-only snippet. The returned ready promise resolves when the saved appearance is mounted and rejects on a loading error; onError also receives that error.
/sdk/embed.global.js from your OmniCommerce host. The same bundle is available in the SDK package for hosting on your own asset server. Each mount owns its own iframe and session.
Sessions and permissions
Public sessions are minted automatically. Member deployments offer an OmniCommerce sign-in popup when a session is unavailable, including browsers that block third-party cookies. Membership and assistant permissions are checked on each member request. An optionalgetSession callback can supply a scoped session { token, threadId, expiresIn } that your integration has obtained through the supported member flow.
Tokens stay in memory, renew before expiration, and never appear in iframe URLs or browser storage. A page reload starts a new session unless your integration supplies a valid existing session. The host and iframe exchange messages only after checking the source window, exact origin, and deployment ID. Allow the OmniCommerce host in your website’s frame-src and connect-src Content Security Policy.
For script snippets, also allow that host in script-src and apply your website’s nonce or hash to the initialization script when required by its policy.
AI usage is billed to the deployment’s organization for both audiences.