BotCreds Agent Artifacts
BotCreds Agent Artifacts gives AI agents a permanent home for their outputs. Post a single HTML file to the REST API. The plugin parses it, extracts scripts and styles, saves them as static files, enqueues them properly via WordPress APIs, and serves the result at a clean public URL with strict security headers. No build tools. No infrastructure. One API call. How It Works POST raw HTML to /wp-json/wp/v2/artifacts The plugin extracts and blocks and saves them as static files in wp-content/uploads/artifacts/{id}/ JS and CSS are enqueued via wp_enqueue_script() / wp_enqueue_style() — no inline scripts in rendered output The HTML body is sanitized with wp_kses() and an expanded allowed-tags list (canvas, SVG, inputs, video, audio, data-* attributes) The artifact is served at yourdomain.com/artifacts/{slug}/ with a strict Content Security Policy From the caller’s perspective: POST HTML, get URL. Everything else happens server-side. Features Deployment Single REST API call — no SDK, no library, any HTTP client works Update artifacts in place — POST to /wp-json/wp/v2/artifacts/{id} and the public URL stays the same Optional artifact_description field for internal documentation Head content preservation — tags and other elements from submitted HTML are preserved in output External script support — tags are registered as external dependencies and enqueued alongside local assets Asset cache busting — enqueued files are versioned with filemtime() so browsers fetch updates automatically Clean redeploys — old asset files are deleted before new ones are written Security Content Security Policy on every artifact page — blocks external script injection and cross-origin data exfiltration by default Trusted CDN list out of the box: cdn.jsdelivr.net, unpkg.com, cdnjs.cloudflare.com, esm.sh, cdn.skypack.dev — scripts and styles load from these without any configuration Per-artifact API allowlist — artifacts that call external APIs declare their origins via an HTML pragma comment ( ) or a deploy-time meta field; the plugin adds them to connect-src automatically Additional security headers: X-Content-Type-Options, X-Frame-Options, Referrer-Policy Custom capability type — artifact capabilities are separate from standard post capabilities; only Administrators can create artifacts by default Developer Hooks botcreds_agent_artifacts_csp — filter the full CSP header value for any artifact botcreds_agent_artifacts_allowed_html — filter the wp_kses allowed-tags array botcreds_agent_artifacts_grant_to_role() — helper to grant capabilities to additional roles Custom template — drop single-artifact.php in your active theme to replace the render template Use Cases OpenClaw (AI personal assistant) OpenClaw agents can deploy interactive dashboards, daily digests, data visualizations, and mini-apps in a single tool call. Generate the HTML, POST it, get the URL — no manual steps, no context switching. For artifacts that fetch live data, add a pragma comment to the HTML and the CSP is updated automatically: For recurring reports (daily digests, weekly summaries), store the artifact ID after the first deploy and update in place on subsequent runs. The URL never changes. Claude Code (terminal-based coding agent) Claude Code sessions can invoke a shell deploy script directly after generating output. Add a scripts/deploy-artifact.sh to your project and reference it in your CLAUDE.md — Claude will use it to ship outputs without leaving the terminal. No manual copy-paste, no browser switching. Codex (OpenAI coding agent) Same pattern as Claude Code. Add deployment instructions to your AGENTS.md and Codex can write HTML, call the deploy script, and report the live URL — all in one agent run. GitHub Actions (versioned project) For projects that build a static HTML output — dashboards, reports, documentation, changelogs — a GitHub Actions workflow can deploy to an artifact on every push to main. The artifact ID is stored as a repository variable so the public URL stays stable across all future deploys. Push → build → deploy → done. Example: Deploy via REST API curl -X POST "https://your-site.com/wp-json/wp/v2/artifacts" \ -u "username:application-password" \ -H "Content-Type: application/json" \ -d '{ "title": "My App", "status": "publish", "meta": { "artifact_html": " Hello. ", "artifact_description": "Built by my AI agent" } }' The response link field is the public URL of the deployed artifact. Example: Artifact with Live Data Include the fetch pragma in your HTML — no configuration needed: fetch('https://api.openweathermap.org/data/2.5/weather?q=Denver&appid=YOUR_KEY') .then(r => r.json()) .then(d => document.getElementById('weather').textContent = d.weather[0].description); Example: GitHub Actions Deployment name: Deploy Artifact on: push: branches: [main] jobs: deploy: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - run: npm ci && npm run build - name: Deploy to Artifact env: WP_SITE: ${{ secrets.ARTIFACT_WP_SITE }} WP_USER: ${{ secrets.ARTIFACT_WP_USER }} WP_PASS: ${{ secrets.ARTIFACT_WP_PASS }} ARTIFACT_ID: ${{ vars.ARTIFACT_ID }} run: | PAYLOAD=$(jq -n --arg title "My Dashboard" --rawfile html dist/index.html \ '{title: $title, status: "publish", meta: {artifact_html: $html}}') ENDPOINT="$WP_SITE/wp-json/wp/v2/artifacts" [ -n "$ARTIFACT_ID" ] && ENDPOINT="$ENDPOINT/$ARTIFACT_ID" curl -sf -X POST "$ENDPOINT" -u "$WP_USER:$WP_PASS" \ -H "Content-Type: application/json" -d "$PAYLOAD" | jq -r '.link'
Top keywords
- artifact22×2.65%
- html17×2.05%
- wp17×2.05%
- artifacts14×1.69%
- deploy10×1.21%
- agent8×0.97%
- id8×0.97%
- post8×0.97%
- url8×0.97%
- api6×0.72%
- artifact id6×0.72%
- call5×0.60%
Tiny Talk
Tiny Talk is a powerful AI agent platform that helps you engage with your audience 24/7. This official WordPress plugin makes it easy to integrate Tiny Talk agents into your WordPress site. 💬 Why Use Tiny Talk? ✅ Real-Time Help Desk: Chat instantly with visitors and customers to solve their issues and answer questions whether from web or WhatsApp (more coming soon) ✅ Knowledge Base: Create knowledge base from your documents using formats like PDF, DOCX, XLSX, PPTX, MD, TXT, CSV. ✅ Web Crawler: Use our web crawler to scrape your website content to enrich your knowledge base. ✅ Conversation History: Access previous conversations and do follow-ups. ✅ Customized Messenger: Brand your messenger to match your colors, avatars, and copy. ✅ Workspaces & Members: Create workspaces to isolate agents from each other and invite members to each workspace to help you manage your workload. ✅ Latest AI Models: Use leading AI models from OpenAI, OpenRouter, and Groq. ✅ Custom Domains: Associate an agent with your custom domain like chat.example.com to complete your branding. ✅ Welcome Messages: Use welcome and suggested messages to inspire your visitors for quick start. ✅ Lead Generation: Define form fields and capture leads from your messenger. ✅ Integrations: Make use of Zapier, Pabbly, Google Drive, Slack, Notion, WhatsApp and Webhook integrations to build workflows of your own and collaborate with your teams. ✅ Push Notifications: Receive push notifications on web browsers and stay alerted on every new conversation or message. ✅ Analytics – See how your agents are doing, where your visitors are from and how deep the conversations are. 🌍 Multi-Language Live Chat for Global Support While AI models support dozens of languages, our messenger interface supports 10 languages: Arabic, Dutch, English, French, German, Hungarian, Italian, Japanese, Portuguese, and Spanish to deliver a personalized experience to users in their native language automatically. Key Plugin Features Easy Setup – Just paste your Agent ID and you’re ready to go Multiple Agents – Configure different agents for different purposes (sales, support, etc.) Smart Rules – Automatically show the right agent based on page type, category, URL, or user role Page Override – Manually select which agent appears on specific pages Shortcode Support – Embed chat interfaces anywhere using [tinytalk] WooCommerce Ready – Show product-specific agents on your shop pages Lightweight – Minimal impact on page load times Rule-Based Assignment: Set up intelligent rules to automatically show the right agent: By Post Type (e.g., all WooCommerce products) By Category/Taxonomy (e.g., specific product categories) By URL Pattern (e.g., /pricing/*, /help/*) By Page Template By User Role (logged in vs guest) Shortcodes: [tinytalk] – Display default/rule-matched agent [tinytalk agent="Sales Agent"] – Display specific agent by name [tinytalk agent_id="550e8400-e29b-41d4-a716-446655440000"] – Display specific agent by ID [tinytalk width="100%" height="500" type="iframe" styled="yes"] – Embed as styled iframe with custom dimensions [tinytalk width="100%" height="500" type="iframe" styled="no"] – Embed as plain iframe with custom dimensions Third-Party Services This plugin connects to the Tiny Talk external service to provide AI agent chat functionality on your website. What is Tiny Talk? Tiny Talk is an AI agent platform that powers the chat widget displayed on your site. A Tiny Talk account is required to use this plugin. When does the plugin connect to Tiny Talk? When the plugin is enabled and an Agent ID is configured, a JavaScript file is loaded from the Tiny Talk CDN (cdn.tinytalk.ai) on your site’s frontend pages. This script renders the chat widget and handles communication between your visitors and the Tiny Talk service. What data is transmitted? When a visitor interacts with the chat widget, their messages and the current page URL are sent to Tiny Talk’s servers for processing. No data is collected or transmitted until a visitor actively engages with the chat widget. Service links Tiny Talk AI Terms of Service Privacy Policy