Developer API

Free

Build on DChat

Connect DChat to your own systems

DChat has a REST API for conversations, messages, contacts, labels and inboxes, documented on your own server at /api/docs. Webhooks tell your systems when something happens, and the widget has a JavaScript SDK for your own site.

The developer tools are free on every edition. This page describes the ASP.NET Core edition of DChat 2.0.6; the separate Web Forms package does not include the 2.0.5 or 2.0.6 additions.

Free

REST API and tokens

Each agent creates personal access tokens, read-only or read and write, with an expiry. A token can do only what its agent can do.

Free

Signed webhooks

Events such as a conversation starting, a new message, a status change, an inbound email or an SLA breach are posted to your URL, signed with HMAC-SHA256.

Free

Widget SDK and identity

Open, close and reset the widget from your page, listen for events, and pass a signed-in user with an HMAC so agents see a verified identity.

API reference on your own server

The reference at /api/docs lists the endpoints an integration needs, and the OpenAPI 3.0 file imports into Postman, Insomnia or a client generator.

DChat API reference page describing authentication with a personal access token and the list conversations endpoint with its parameters

Verified visitors

When your server signs the visitor's identifier, the conversation is marked as a verified identity for agents.

DChat conversation header with a Verified identity badge next to the web chat channel

Included

  • REST API under /api/v1
  • Personal access tokens, read or read and write
  • Up to 25 active tokens per agent, with expiry
  • Administrators can see and revoke any token
  • API reference at /api/docs with an OpenAPI 3.0 file
  • Webhooks signed with HMAC-SHA256 and a timestamp
  • Durable webhook delivery with retries
  • Widget SDK: setUser, setCustomAttributes, open, close, toggle, reset and events
  • Identity verification with an HMAC-SHA256 identifier hash
  • Option to require verified identity

New in 2.0.6

Agent bots, rich messages and tighter tokens

Interactive messages through the API and the token restrictions apply to every edition. Agent bots are part of Premium.

Premium

Agent bots

An agent bot is your own service. DChat sends each customer message to its webhook, signed with HMAC-SHA256. The bot answers in the webhook response or later through the bot API with its token, with text, buttons, a form or a card, or hands the conversation to the team. A bot that fails or stays silent past its timeout is handed over automatically. The protocol is documented, with a short example bot.

Free

Interactive messages

The reply endpoint can send buttons (up to ten), a form (up to five text, email or choice fields) or a card with a title, text, image and link. Channels without buttons get a numbered text version.

Free

New webhook event

Merging two conversations fires CONVERSATION_MERGED, so your own systems can follow the change.

Free

What an API token cannot do

Some actions now need a person signed in, never a token: changing passwords or two-factor settings, editing agents or roles, rotating channel and bot secrets, changing single sign-on, Slack or widget domain settings, revealing the widget identity secret, and emailing transcripts.

Details

Webhook events

CONVERSATION_START, CONVERSATION_MESSAGE, CONVERSATION_END, CONVERSATION_STATUS_CHANGED, VISITOR_ONLINE, VISITOR_WAITCHAT, AGENT_ONLINE, AGENT_OFFLINE, OFFLINE_MESSAGE, EMAIL_RECEIVED, SLA_BREACHED and AUTOMATION_RULE.

Identity verification

Your server computes HMAC-SHA256 of the visitor's identifier with a secret set in the dashboard, and the page passes it to ZChat.setUser. Verified visitors are filed under their own contact.

Tokens act as their agent

A token has its agent's rights as they are at each request, never more. A read-only token can only read, and no token can create another token.

Scope of the reference

The /api/docs reference covers conversations and messages, contacts, labels, inboxes, the channel webhook and the token's own identity. It is not a list of every endpoint the dashboard uses.

Questions we get asked

Is the API part of a paid tier?

No. The REST API, access tokens, webhooks, the widget SDK and identity verification are in the free Community edition. Calls that touch a paid feature answer with a clear requires_premium or requires_enterprise code.

How are webhooks signed?

Each request carries an X-ZChat-Signature header: sha256 followed by the hex HMAC-SHA256 of the timestamp, a dot and the body, using your webhook secret.

How does widget identity verification work?

Your server signs the visitor identifier with HMAC-SHA256 and a secret from the dashboard. The page passes the identifier and the hash to ZChat.setUser, and DChat marks the visitor as verified.

Integrate without an extra plan

The API, webhooks and widget SDK are free with unlimited agents on every edition.

Self-hosted customer support software

Deploy live chat on your own terms, not on someone else's pricing model.

DChat gives you the installable server, web dashboard, website widget, and desktop agent tools in one self-hosted product, with live chat free to run, and an AI agent that answers, acts with the approvals you set and hands off to your team when you want one. Run it on infrastructure you trust, on the model you choose.

Deployment

Install on Windows or Linux, behind IIS or Nginx, in a VM, or in Docker if that fits your stack.

Commercial model

Live chat is free with unlimited agents. Premium, with the AI agent, is billed per agent per month, never per conversation.

AI Flexibility

Run the AI agent on a local Ollama model, or connect OpenAI and Anthropic with your own provider accounts.