Context Assistant

Description

Context Assistant adds an AI chat widget to your site — but unlike a
generic chatbot, it is built around three ideas:

  • Page context. The assistant knows where the visitor is: which
    post or product is open, its title and categories. Never the page
    body, never form input, never cookies — only small facts you allow.
  • Answers from your content. Published posts, pages and products
    are synced into a knowledge base; the assistant answers questions
    about your site, grounded in retrieval, not model memory.
  • Safe actions. The assistant can act — search content, draft
    posts, check a customer’s own order, update stock — always with the
    signed-in user’s own WordPress capabilities, and any change only
    after an explicit preview card and an Apply click. Deletions need a
    second confirmation and go to the trash, never permanent removal.

The heavy lifting (models, retrieval, orchestration) runs on a Context
Assistant server; this plugin connects your site to it. Your secret API
key is encrypted at rest and never leaves your server — visitors only
ever hold short-lived tokens.

WooCommerce: with WooCommerce active, the assistant additionally
searches the catalog with live prices and stock, shows a signed-in
customer the status of their own orders, and lets shop managers update
stock through the preview/Apply flow.

For developers: add your own assistant tools with the
context_assistant_tools filter, extend the page context with
context_assistant_page_context, and control widget visibility with
context_assistant_should_render. WP-CLI: wp context-assistant sync.

External services

This plugin does not work on its own: the models, retrieval and
orchestration run on a Context Assistant server that you configure
in Settings Context Assistant (the API URL). That server is
either your own self-hosted instance or the hosted Context Assistant
service — the plugin talks only to whichever URL you enter.

What the plugin sends to that server, and when:

  • When a visitor opens the chat — a short-lived embed token is
    minted for the browser, and the page context you allowed (page URL,
    titles, public taxonomy terms; each behind its own privacy toggle,
    never the page body or form input) is attached to the conversation.
  • On each message — the visitor’s message text and that page
    context, so the assistant can answer. Visitors are identified by an
    anonymous cookie, not by name.
  • When knowledge sync is enabled — the text of your published
    posts, pages and products (never drafts or private content), so the
    assistant can answer from your own content.
  • When the Remote Tools bridge is enabled — the server calls back
    into your site to run tools under the signed-in user’s own WordPress
    capabilities; your secret API key stays encrypted on your server and
    is never sent to the browser.

Conversation transcripts are stored on that server and can be exported
or deleted (see the FAQ). No data is sent anywhere else.

If you use the hosted Context Assistant service, it is operated
under its own terms of service and privacy policy:
Terms: https://contextassistant.io/terms/
Privacy: https://contextassistant.io/privacy/

Screenshots

Blocks

This plugin provides 1 block.

  • Context Assistant Shows the Context Assistant chat widget on this page (useful when the widget is limited to selected post types).

Installation

  1. Install and activate the plugin.
  2. Open Settings Context Assistant.
  3. Enter your API URL, secret key (ca_sk_…) and Assistant ID from the Context Assistant console, and make sure your site’s origin is allow-listed on the assistant.
  4. Press Check connection — three green checks mean the widget is live on your site.
  5. Optional: enable Knowledge base sync so the assistant answers from your content, and the Remote Tools bridge so it can act.

FAQ

Which key goes into the settings?

The Context Assistant secret key (ca_sk_…) from your console. The AI
provider key (e.g. an OpenAI sk-… key) is configured on the Context
Assistant server and never enters WordPress.

What data does the widget send?

Per message: the page URL, titles and public taxonomy terms — each
behind its own toggle, and never the page body. The knowledge base
sync sends only published content. Visitors are identified by an
anonymous cookie; the plugin sets no tracking cookies beyond it.

Does it work with page caching?

Yes. Anonymous pages carry nothing user-specific — tokens are fetched
by the browser after the page loads, so full-page caches keep working.

Can visitors change my site through the assistant?

No. Guests only see read-only tools over already-public content.
Mutating tools exist only for signed-in users with the matching
WordPress capabilities, and every mutation requires an explicit
confirmation in the chat.

Can I export or delete the conversation history?

Yes. Transcripts are stored on the Context Assistant server, not in
your WordPress database. The server exposes an export of all
conversations and deletion of any single conversation, so a visitor’s
data can be handed over or erased on request (GDPR). Self-hosting the
server keeps that data entirely under your control — see below.

Where are the widget’s readable sources?

The plugin enqueues a minified assets/embed.js. Its full, unminified
source ships beside it as assets/embed.src.js, and both are built
from packages/embed-sdk in the public repository — no build step is
hidden.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Context Assistant” is open source software. The following people have contributed to this plugin.

Contributors

Translate “Context Assistant” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

0.1.0

  • Initial release: chat widget with page context, embed-token security,
    knowledge base sync (RAG), 25 capability-scoped WordPress and
    WooCommerce tools, and a WP-CLI sync command.