{
  "id": "website",
  "name": "Website chat widget",
  "category": "connector",
  "recipe": "connector",
  "protocol": "sdk",
  "source": "https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API",
  "referenceDate": "2026-09-29",
  "verification": {
    "setup": "prepared",
    "session": "not_run"
  },
  "notes": "Use an authenticated server-side session and same-origin CSRF protection. Map the session user to a Jesse key on the server. The browser never receives the Jesse key.",
  "contractVersion": "1.0.0",
  "endpoint": "https://jesse.my/api/v1/chat/completions",
  "apiRoot": "https://jesse.my/api",
  "model": "jesse",
  "files": [
    {
      "name": "connector.mjs",
      "format": "javascript",
      "content": "import { JesseClient } from '../shared/client_sdk.mjs';\nimport { createChatConnector } from '../shared/client_connectors.mjs';\n\nexport function createJesseConnector({ verifyEvent, keyForActor, store }) {\n  return createChatConnector({\n    verifyEvent, store,\n    clientForActor: async (platform, actor) => new JesseClient({ apiRoot: \"https://jesse.my/api\", apiKey: await keyForActor(platform, actor) }),\n  });\n}\n"
    },
    {
      "name": "event.json",
      "format": "json",
      "content": "{\n  \"platform\": \"website\",\n  \"actor\": \"authenticated-user-id\",\n  \"conversation\": \"authorized-conversation-id\",\n  \"eventId\": \"stable-delivery-id\",\n  \"text\": \"What is 17 * 23?\"\n}\n"
    },
    {
      "name": "README.md",
      "format": "markdown",
      "content": "# Website chat widget with Jesse\n\nUse an authenticated server-side session and same-origin CSRF protection. Map the session user to a Jesse key on the server. The browser never receives the Jesse key.\n\nAPI root: https://jesse.my/api\nOpenAI-compatible base URL: https://jesse.my/api/v1\nEndpoint: https://jesse.my/api/v1/chat/completions\nModel: jesse\nKey environment: JESSE_API_KEY\n\nKeep the key in the app's credential store or launch environment. These files are merge snippets; never overwrite existing providers or settings. GUI apps may not inherit shell environment variables.\n\nClient budgets: context 10000, output 4096. These are conservative defaults, not server capacity claims. Keep general vision, embeddings, audio, provider-hosted web tools and automatic retry of billable turns disabled.\n\nFull Jesse API access: shared/client_sdk.mjs supports 31 operations. The MCP bridge exposes the same operation list where the host supports MCP. Preserve the full Jesse receipt. Tool calls remain proposals and are not executed by the bridge.\n\nVerification: setup prepared; current full application session not_run. Run a chat, a streamed reply, a refused credential, a failing tool result and a file task with its actual tests before qualifying a coding-agent release.\n\nUpstream: https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API\n"
    }
  ]
}
