Skip to content

Developers

A chat platform you can build on

Program the widget from your page, sync conversations with your systems through the REST API and react to events with signed webhooks.

Webhook delivery
POST /zebchat/webhooks HTTP/1.1
ZebChat-Event: message.created
ZebChat-Signature: t=1791158400,v1=5f8c0e…

{
  "id": "evt_0192…",
  "type": "message.created",
  "organizationId": "org_0192…",
  "data": {
    "message": {
      "id": "msg_…", "conversationId": "conv_…", "seq": 3,
      "senderType": "visitor", "body": "Where is my order?"
    }
  }
}
A signed webhook delivery (abridged). See the webhooks docs for the full payload.

Highlights

What you get

Build on ZebChat: a REST API with scoped API keys, signed webhooks with retries and replays, realtime Socket.IO events, an OpenAPI spec and a JavaScript API for the widget.

  • REST API

    Scoped API keys, cursor pagination, consistent errors, per-key rate limits and an OpenAPI spec.

  • Webhooks

    Signed with HMAC, six retries with backoff, a delivery log and one-click replays.

  • Realtime events

    Socket.IO namespaces with versioned envelopes and gap-free per-conversation ordering.

  • JavaScript API

    Open the widget, start chats, identify users, add tags and track events from your page.

  • Identity verification

    Sign your users’ ids on your server so agents know who they are talking to.

  • Safe by default

    Webhook and action calls are HTTPS-only, with SSRF protection and no redirects.

Integrate

Connect ZebChat to the rest of your stack

API keys and webhooks are part of the Pro and Enterprise plans. Keys carry scopes limited by the role of the member who created them.

  • Webhooks auto-disable after repeated failures, and you get an email
  • AI actions let the assistant call your endpoints with the same signing scheme
  • Every org-scoped REST route accepts API keys
  • Prefixed public ids such as conv_… and vis_… everywhere

FAQ

Frequently asked questions

Which plans include the REST API and webhooks?

API keys and outgoing webhooks are included in the Pro and Enterprise plans. The widget’s JavaScript API works on every plan.

How do I verify a webhook?

Every delivery carries a ZebChat-Signature header with a timestamp and an HMAC-SHA256 of the body. Recompute it with your endpoint’s secret and reject old timestamps.

Explore

Start talking to your visitors today

Free for one agent and one website, with no card required. Upgrade when your team grows.