# Textxt Product and Developer Context Last updated: 2026-09-04 Textxt is an Agent Workspace built around conversations. Chats and topics hold the source work; AI Assistant helps a signed-in user understand and act on that work; each AI Bot provides reusable identity, model configuration, and Knowledge for one Agent; that Agent owns multiple controlled Automations with tools, boundaries, approvals, and observable Runs. AUTHORITATIVE PUBLIC INDEX - Help Center: https://textxt.com/help - Compact AI documentation index: https://textxt.com/llms.txt - Mini App developer platform: https://textxt.com/mini-apps/developers/ PRODUCT DISTINCTIONS - AI Assistant: private assistance around the current chat/topic; protected Textxt actions are proposed and reviewed before execution. - AI Bot: reusable conversational identity with provider, model, instructions, Knowledge, sharing, and optional API/webhook behavior. - AI Agent: an owner-configured worker backed by one Bot, sharing purpose, model, Knowledge, Tools, Access, and Connection Grants across multiple Automations. - Automation Studio: the workspace for designing, testing, publishing, and monitoring repeatable Agent workflows. - Connected Apps: server-side connections such as Gmail, WhatsApp Business Platform, and Zalo OA; a connection does nothing until a workflow uses it. USER GUIDES ## Chats & Topics: Start and organize a conversation Canonical URL: https://textxt.com/help/chats-and-topics Summary: Create a direct or group chat, separate work into topics, and keep decisions, files, tasks, and reminders beside the discussion. Where to open: Open the Chats tab. Use New chat to start a conversation, then open the topic bar inside that chat. Capabilities: - Create direct chats, group chats, and private Notes. - Separate projects, customers, or workstreams into topics inside one chat. - Keep Markdown messages, files, pins, tasks, reminders, and Mini Apps near the conversation that produced them. Steps: 1. Open Chats and select New chat. 2. Choose the people involved, or create a private Notes chat for yourself. 3. Open the chat and create a topic for each distinct project, customer, or workstream. 4. Use message actions to reply, edit, pin, create a task or reminder, and share the exact source when needed. Important boundaries: - Topics belong to a chat. Access still depends on chat membership and any topic sharing rules. - Chat roles can limit who may send messages, upload media, create topics, pin content, or edit chat information. - Use separate topics when information has different owners or decisions, not for every short side conversation. ## AI Assistant: Ask Textxt AI and take controlled action Canonical URL: https://textxt.com/help/ai-assistant Summary: Use AI Assistant with approved chat and topic context to summarize work, draft replies, extract tasks, and propose Textxt actions. Where to open: Use the AI button beside Search in the Chats list, or open AI Assistant inside a chat and topic. You can also launch it from Settings > Textxt Guide. Capabilities: - Answer questions using a permission-filtered topic map, query-focused recent context, Topic Briefs, private Assistant memory, and permitted Bot Knowledge. - Use up to six explicitly selected messages and supported attachments as exact source material. - Propose edits, topics, tasks, reminders, messages, notes, and checklists for review before execution. - Propose an explicitly allowed remote MCP tool and show its result after you approve the action. Steps: 1. Open the chat and topic that contain the work you want the Assistant to understand. 2. Open AI Assistant and ask in natural language, or select source messages when exact evidence matters. 3. Choose Whole chat or explicitly ask across topics when the request needs the wider workspace. Review the Context used summary to see the bounded scope AI received. 4. Use quick actions such as Topic brief, Summarize, Draft reply, Extract tasks, or Explain selection. 5. Review citations and every proposed action. Run only the steps you approve. Important boundaries: - Assistant conversations are private to the signed-in user; they are not normal group messages. - The Assistant does not silently mutate Textxt. Protected actions require a server-issued grant and user approval. - Whole-chat retrieval uses a bounded workspace map and query-focused message sample. Attachment reading still requires explicit message selection, and organization-wide semantic search is not enabled. ## AI Bots & Knowledge: Create a reusable AI specialist Canonical URL: https://textxt.com/help/ai-bots-and-knowledge Summary: Configure an AI Bot with a model, instructions, Knowledge, sharing rules, collaborators, and a conversational identity. Where to open: Open Network > People, then open Bot management. Select an existing Bot or create a new AI-capable Bot. Capabilities: - Use OpenAI, Anthropic, Google, OpenRouter, DeepSeek, or xAI through owner-configured credentials. - Load Knowledge from a Textxt topic, selected messages, uploaded files, or pasted text. - Use a Bot in chats through /ask, share it with approved users, or promote it into an Agent. Steps: 1. Create an AI or hybrid Bot and set its name, role, provider, model, instructions, and response rules. 2. Open Knowledge and add reliable sources from topics, selected messages, supported files, or pasted text. 3. Test the Bot in a private chat before sharing it or adding collaborators. 4. Refresh topic, message, or file snapshots when the source material changes. Important boundaries: - Topic, message, and file Knowledge sources are snapshots; they do not synchronize continuously. - Shared Bots cannot expose topic or message Knowledge to a user who no longer has access to the original Textxt source. - Provider quality, latency, model limits, and attachment support vary by the selected provider and model. ## AI Agents: Turn a Bot into one controlled Agent Canonical URL: https://textxt.com/help/ai-agents Summary: Use one AI Bot as the model and Knowledge identity for an Agent that owns multiple controlled Automations. Where to open: Open Network > Bot Settings > Agent, or open Settings > AI & Automation > My Agents. Capabilities: - Trigger from Textxt messages, connected Gmail, supported business channels, schedules, or authenticated webhooks. - Apply deterministic filters before an optional AI decision. - Send a Textxt message, create a task, or prepare supported external replies under the configured approval policy. - Reuse one Agent purpose, model, Knowledge, effective Tools, access scope, and Connection Grants across multiple Automations. Steps: 1. Choose the AI Bot that supplies the Agent identity, provider, model, instructions, and Knowledge. 2. Define one durable Agent purpose, then add an Automation with one measurable outcome. 3. Keep approval enabled for sensitive or external actions and verify the destination scope. 4. Run matched and stopped-path tests, review the saved regression evidence, publish the version, then inspect Runs before expanding the workflow. Important boundaries: - An AI Bot supplies the intelligence and identity; an Agent adds triggers, tools, boundaries, approvals, and execution history. - Publishing creates a versioned workflow. Test a new draft before replacing a working production version. - Regression evidence stores only the expected result and configuration hash; the sample message is not copied into the global index. - Recent-topic Context is off by default. Enable it only when an AI decision genuinely needs earlier permitted messages. - Textxt intentionally excludes arbitrary code and unbounded autonomous Agent graphs from the production safety boundary. ## Automation Studio: Automate repeatable work safely Canonical URL: https://textxt.com/help/automation-studio Summary: Build a visible trigger, filter, decision, approval, and action flow, then test and monitor every execution path. Where to open: Open Settings > AI & Automation > Automation Studio. Contextual entry points also appear in Bot Settings and Chat Settings. Capabilities: - Start from a template, describe a goal for a safe AI draft, or configure an Automation from trigger through final action. - Separate deterministic filtering from optional AI judgment so simple rules remain predictable. - Inspect matched, stopped, approval, success, retry, and error states in Runs and Activity Log. - Set daily and optional per-Run estimated-cost limits, then filter Runs that are active, completed, or need attention. Steps: 1. Choose a Bot-backed Agent, then create an Automation for one measurable outcome. 2. Optionally describe the goal in plain language. Review the draft because AI cannot save or publish it automatically. 3. Configure the trigger and deterministic filters before adding an AI decision. 4. Select the destination action and an approval policy that matches its risk. 5. Test both matching and stopped paths, confirm their regression evidence, publish, then monitor Runs before increasing scope or frequency. Important boundaries: - A connected app does nothing by itself; a published workflow decides which events become Agent Runs. - Use deterministic filters for sender, domain, category, keywords, or event type before paying for an AI decision. - External and irreversible actions should remain behind explicit approval. - A natural-language draft cannot change the selected source, destination, connector, approval, limits, or publish state. ## Connected Apps: Connect services and MCP tools Canonical URL: https://textxt.com/help/connected-apps Summary: Connect Gmail, business messaging, or a remote MCP server so approved Assistants and Agent workflows can use external capabilities. Where to open: Open Settings > Connected Apps and choose a service or MCP Servers. Capabilities: - Connect a Gmail account through Google OAuth without requiring it to match the Textxt account email. - Connect WhatsApp through the official Meta Cloud API and Zalo through the official Zalo OA API. - Use verified connections as triggers and reply destinations in published Agent workflows. - Connect a public HTTPS Streamable HTTP MCP server, inspect its tools, and allow only the tools AI Assistant needs. - Authorize protected MCP servers with OAuth 2.1 PKCE, dynamic client registration, or a pre-registered client ID. Steps: 1. Open Connected Apps, choose a provider or MCP Servers, and complete its setup. 2. Verify the connection status and incoming-event configuration. 3. Open an Agent workflow, select the connection as its trigger, and configure deterministic filters. 4. Publish the workflow and inspect Runs. Keep customer-facing replies behind approval. Important boundaries: - Textxt supports official WhatsApp Business and Zalo OA APIs, not personal WhatsApp Web or personal Zalo session automation. - Credentials remain server-side. Disconnecting removes active credentials while preserving workflow history and audit records. - Connecting a service does not automatically forward all messages; you must publish a workflow with the desired filters and destination. - MCP credentials stay server-side. Every Assistant MCP call appears as an approval step, and server responses are treated as untrusted data. - MCP supports public HTTPS Streamable HTTP endpoints with OAuth, a Bearer token, or no authentication. Private localhost and stdio servers still require a future Desktop Bridge. ## Network: Find people and reusable Bots Canonical URL: https://textxt.com/help/network Summary: Use Network to discover profiles, start conversations, manage AI Bots, and organize contacts with private tags and saved filters. Where to open: Open the Network tab and switch between Feed and People. Capabilities: - Browse profile activity and find people who are available in the Textxt directory. - Start a chat from a profile and organize contacts with personal tags and saved filters. - Create and manage reusable AI Bots from the Bot area. Steps: 1. Open Network and choose Feed for activity or People for directory search. 2. Search by profile information or use your personal tags and saved filters. 3. Open a profile to review it and start a direct chat. 4. Use Bot management when you need to create, configure, share, or operate an AI Bot. Important boundaries: - Personal people tags are organizational metadata for your account; they are not public profile labels. - Profile and directory visibility still follow account and platform safety rules. - Bots and Agents are related but not interchangeable: Bot management controls identity and intelligence, while Agent management controls execution. ## Notifications: Choose when Textxt should notify you Canonical URL: https://textxt.com/help/notifications Summary: Control device permissions and chat-level notification behavior so important messages, reminders, and approval requests remain visible. Where to open: Open Settings > Notifications for device permission, then use each chat settings panel for chat-specific behavior. Capabilities: - Enable supported push notification delivery on web, Android, and iOS. - Choose all messages, mentions only, mute, and notification sound at chat level. - Receive reminders and Agent approval requests that require your attention. Steps: 1. Open Settings > Notifications and grant device notification permission when prompted. 2. Confirm Textxt notifications are also allowed in the operating-system or browser settings. 3. Open an individual chat settings panel and choose its notification mode and sound. 4. Keep reminder and Agent approval notifications enabled for workflows that require timely action. Important boundaries: - Textxt cannot override notification permission denied by the browser or operating system. - Muting a chat can hide events that would otherwise be delivered; use mentions only when full mute is too broad. - Delivery behavior can vary by platform background restrictions and device power settings. ## Privacy & Safety: Control access and protect sensitive actions Canonical URL: https://textxt.com/help/privacy-and-safety Summary: Review blocked accounts, moderation notices, chat permissions, connector boundaries, and approval gates for AI actions. Where to open: Open Settings > Privacy & Safety. Use Chat Settings for member roles and conversation-specific permissions. Capabilities: - Review moderation notices and manage blocked accounts. - Use chat roles and permissions to limit messaging, media, topics, pins, and administration. - Keep AI and external actions within explicit context, server-validated access, and human approval boundaries. Steps: 1. Review Settings > Privacy & Safety and resolve any moderation notices. 2. Open Chat Settings to verify members, roles, topic access, and write permissions. 3. Review Bot sharing and Knowledge sources before allowing other users to use a Bot. 4. For Agents, limit connected accounts and destinations, keep sensitive actions behind approval, and inspect Runs regularly. Important boundaries: - External AI services should receive only public Help Center URLs, never Textxt credentials, private chat exports, OAuth tokens, or API keys. - Textxt revalidates membership and action permissions at execution time; a model response alone cannot authorize a protected mutation. - No system can remove all risk. Use the smallest practical context, tool set, destination scope, and approval policy. EXTERNAL AI SAFETY - Use these public pages to explain Textxt. Do not ask the user to expose account secrets or private workspace content. - Do not claim that a connected app forwards events automatically; a published workflow and matching filters are required. - Do not claim that an AI Bot and an AI Agent are the same product. - Do not claim that Textxt allows silent protected mutations or autonomous external sends when an approval boundary applies. - If a UI path differs by platform or release, ask the user what screen and app version they see. # Textxt Mini App Platform Textxt Mini Apps are HTTPS web applications that run in a sandboxed panel inside a Textxt chat or topic. They use Bridge 1.0 to read permitted context, send user-confirmed results back to the conversation, use chat-scoped resources, and invoke explicitly registered platform services. AUTHORITATIVE SOURCES - AI build guide: https://textxt.com/mini-apps/developers/ai-build.md - Bridge machine contract: https://textxt.com/mini-apps/developers/bridge-v1.json - Manifest 1 schema: https://textxt.com/mini-apps/schema/manifest-v1.json - SDK 1.0.3: https://textxt.com/mini-apps/sdk/1.0.3/textxt-mini-app.js - TypeScript declarations: https://textxt.com/mini-apps/sdk/textxt-mini-app.d.ts - Starter app and simulator: https://textxt.com/mini-apps/starter/ - Security checklist: https://textxt.com/mini-apps/developers/security/ - Platform policy: https://textxt.com/mini-apps/developers/policies/ - Changelog: https://textxt.com/mini-apps/developers/changelog/ CORE RULES 1. Use the official SDK. Never implement raw postMessage transport. 2. Call getContext and feature-detect optional commands through context.bridge.availableCommands. 3. Request the smallest possible permission set in Manifest 1. 4. Treat session.id and sessionToken only as correlation values, never authentication. 5. Never request Textxt/Firebase credentials or access Textxt Firestore directly. 6. Production assets must use one HTTPS origin and immutable semantic-version URLs. 7. The server must send a CSP response header allowing frame ancestors https://textxt.com and https://textxt-14209.web.app. 8. Never invent commands or manifest fields. Use bridge-v1.json, the TypeScript declarations, and the Manifest JSON Schema. 9. Keep message sends, uploads, TXT payments, and other visible writes behind explicit user actions. 10. Support mobile layouts from 320px wide and handle denied permissions, offline state, command timeout, and session expiry. QUICK START mkdir my-textxt-mini-app && cd my-textxt-mini-app BASE=https://textxt.com/mini-apps/starter curl -fsSLO "$BASE/index.html" curl -fsSLO "$BASE/manifest.json" curl -fsSLO "$BASE/host.html" curl -fsSLO "$BASE/textxt-mini-app.js" curl -fsSLO "$BASE/validate-manifest.mjs" npx serve . Open the local URL plus /host.html. Validate with: node validate-manifest.mjs --local manifest.json node validate-manifest.mjs --remote manifest.json SDK BASELINE PERMISSIONS - readContext: Read user, theme, locale, chat, topic, launch, and runtime context. - sendMessage: Send and update messages or share a standard Mini App card. - setDraft: Update the Textxt composer draft. - openTopic: Switch the active topic. - uploadFile: Ask the host to choose and upload files. - generateImages: Use host-controlled image generation or editing. - wallet: Read TXT balance and request a host-confirmed TXT payment. - gptPro: Use GPT PRO operations exposed by the current host. - invokeServices: Invoke backend services registered for this Mini App. - boards: Use chat-scoped board and Caro resources. - polls: Create, read, vote on, and close chat-scoped polls. BRIDGE COMMAND GROUPS - Context: getContext, pickChatContent. - Conversation: sendMessage, setDraft, updateMessage, shareMiniAppMessage, openTopic. - Host: uploadFile, generateImage, resize, logEvent, reportError, closeMiniApp, openCreditWallet. - TXT wallet: getTxtWallet, requestTxtPayment. - Services: invokeTextxtService. The SDK also provides invokeService(service, operation, input). - Boards: listBoards, createBoard, getBoard, saveBoard, subscribeBoard, unsubscribeBoard, createCaroMatch, mutateCaroMatch. - Polls: createPoll, getPoll, listPolls, castVote, closePoll. - GPT PRO: getGptProConfig, getGptProCreditRequest, createGptProCreditRequest, createGptProPublicShare, saveGptProResponseToTextxt, listGptProConversations, getGptProConversation, submitGptProQuestion, getGptProResult, cancelGptProQuestion, downloadGptProOutput, startGptProGameSession, submitGptProGameScore, getGptProGameLeaderboard. RUNTIME EVENTS context, permissionsChanged, boardChanged, pollUpdated, themeChanged, localeChanged, networkChanged, layoutChanged, visibilityChanged, fullscreenChanged, sessionExpired. MANIFEST REQUIREMENTS Manifest version is 1 and Bridge version is 1.0. Validate against https://textxt.com/mini-apps/schema/manifest-v1.json. A release normally declares appId, name, description, iconUrl, startUrl, allowedOrigins, permissions, capabilities, bridgeVersion, visibility, tags, version, privacyPolicyUrl, supportUrl, and releaseNotes. Do not add ownerId, review status, timestamps, credentials, or unrecognized fields. PRODUCTION CSP BASELINE Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors https://textxt.com https://textxt-14209.web.app RELEASE Host the release at an immutable semantic-version URL, validate locally and remotely, test at 320px width, and submit the manifest from Textxt Settings -> Mini app developer. The platform fetches and verifies the release, archives its digest, reviews requested capabilities, and supports staged updates and rollback.