Install
1
Download the plugin
Get
thinnest-ai.php from your agent’s Channels page.It is a single file. WordPress accepts a single-file plugin dropped straight
into wp-content/plugins/, which is a much shorter path than unzipping an
archive into the right folder over FTP.2
Upload and activate
Put it in
wp-content/plugins/, then Plugins → activate ThinnestAI.3
Paste your public key
Settings → ThinnestAI, and paste the public key from your Channels page.The field refuses anything that is not a real key rather than storing a typo
— a mistyped key would otherwise render a broken tag on every page of your
site with nothing to say why.
Recognise signed-in customers
This is what the plugin can do that a pasted script tag cannot. Add your identity secret — from the same Channels page — in Settings → ThinnestAI. WordPress already knows who is reading the page, and the plugin signs that user’s id server-side. The result: a logged-in customer’s site chat, their WhatsApp messages and their history become one customer in your inbox, instead of a stranger every time.The secret never reaches the page. Only an HMAC of the user id does, and a
digest of one id tells an attacker nothing about any other.Leave the field empty and everything else still works — visitors are simply
anonymous, which is the safe default rather than a broken state.
What the plugin deliberately does not do
- No tracking, no phoning home, no version check. It emits one script tag. A plugin that talks to its vendor on every page load is one a security review removes.
- No admin notices, no upsell, no dashboard widget.
- No jQuery, no dependencies, no build step.