Files
libredesk/scripts/tools-server/README.md
T
Abhinav Raut ae44e7f4db expand AI tool context and let contacts correct their email
Custom HTTP tools now get more identity context. Each call sends the
contact id, contact type, conversation UUID, and inbox id as headers,
and the contact email is read live per call instead of snapshotting it
at run start.

set_contact_email is no longer blocked once an email is known. A
customer who gives a different email (for example after their account
could not be found) can now correct it. Changing the email clears the
verification flag and any pending code first, so a failed clear can
never leave the conversation verified against an unproven address. The
prompt and tool descriptions were updated to guide this flow.

Also fixes some widget and admin UI issues: prechat form validation
now handles required numbers, checkboxes, and links correctly; tool
header rows keep stable keys so removing a row does not shuffle inputs;
the verification toggle uses form state directly; and the livechat
inbox form shows the inbox UUID with a copy button.
2026-07-22 00:58:41 +05:30

2.4 KiB

AI copilot tools test server

A minimal HTTP server for testing AI copilot custom tools locally. Maps a contact's external user id (sent by libredesk in the X-Libredesk-Contact-External-Id header) to fake account data. Edit the users map in main.go to add test users.

Run

go run ./scripts/tools-server

Listens on :7070 by default (-addr to change). Every request logs the contact headers and the raw args JSON the model sent.

Headers libredesk sends

On every custom tool call libredesk injects the contact and conversation context server-side (the model never sees or controls these):

Header Value
X-Libredesk-Contact-Id internal contact id
X-Libredesk-Contact-External-Id external user id (from the livechat JWT), if any
X-Libredesk-Contact-Type contact or visitor
X-Libredesk-Contact-Email contact email, if known
X-Libredesk-Contact-Verified true only after OTP/JWT identity verification
X-Libredesk-Conversation-UUID conversation uuid
X-Libredesk-Inbox-Id inbox id

Trust X-Libredesk-Contact-Email for sensitive lookups only when X-Libredesk-Contact-Verified is true; a visitor can self-claim any address.

Endpoints

Endpoint Returns
/account name, email, plan, KYC status
/orders recent orders with status
/balance account balance

Tool setup (Admin -> AI -> Tools)

For each endpoint create a tool with:

  • Method: POST
  • Auth header: X-Api-Key
  • Auth value: test-secret-token
  • Parameters: leave empty

Example: name get_account, URL http://localhost:7070/account, description "Get the customer's account details: name, email, plan, and KYC status."

Test contacts

Set the contact's external user id and email to one of:

Error paths: bad API key -> 401, missing external id -> 400, unknown id -> 404, email mismatch -> 403.