AI customer support for your Next.js app.
Not a chat bubble pasted onto your site. Support that knows your product, recognizes the signed-in user and reads the account data your server allows — wired into the session your app already has.
One CLI command, one instruction to your coding agent, and a finish line in production. App Router or Pages Router. From $19 a month with unlimited teammates.
14-day free trial · 50 AI conversations · no card
The widget, once, in the root layout
Your root layout stays as it is — a Server Component, no 'use client' needed. It renders a plain script tag with your public id into the served HTML; the widget script itself then runs in the browser.
app/layout.tsx
import onetwoagent from '../.onetwoagent.json' // inside <body>, after the app's content:<script src="https://widget.onetwoagent.com/widget/v1.js" data-id={onetwoagent.publicId} defer/>
What lands inside your app
- 01
Product knowledge
Answers from your help center, docs and website, in the user’s language.
- 02
The signed-in user
Your server vouches for who is asking, with the session you already have.
- 03
Their account data
A signed snapshot of what they can see, expiring within 5 minutes.
- 04
Fresh read-only checks
Sections you approve (subscription, access, usage, jobs, integrations) and up to 8 support views, re-checked against the live session.
- 05
Your team, any time
Any teammate can take over from one inbox; the AI stays silent while they do.
Your coding agent does the integration.
You run one command and give one instruction. You don’t explain your auth library, database or hosting.
You run
npx -y @onetwoagent/cli@latest init --browser
Approve it in the browser. It writes .onetwoagent.json, puts the identity secret in .env.local and installs the OneTwoAgent skill.
You say
Integrate OneTwoAgent fully into this app and deploy it. Use the installed OneTwoAgent skill and finish by verifying production
Paste it into Claude Code, Codex, Cursor or another coding agent with a terminal.
It inspects
onetwoagent inspect
Finds the app folder (also in a monorepo), App or Pages Router, your auth library, your deployment and what’s already there.
It writes
npm i @onetwoagent/integration
Installs the package with your package manager and adds the files shown above — only your mapping is app-specific.
It ships
npx -y @onetwoagent/cli@latest env push --to vercel
Sets both secrets in production (on Vercel with this command, names only on screen) and deploys the way your repository already deploys.
It verifies
npx -y @onetwoagent/cli@latest doctor --json
Changes only what doctor reports until production verifies. It stops only for browser approvals, interactive logins and one signed-in visit.
Paste into your coding agent, in your Next.js project
Run `npx -y @onetwoagent/cli@latest init --browser`, then: Integrate OneTwoAgent fully into this app and deploy it. Use the installed OneTwoAgent skill and finish by verifying production.
What stays on the server.
The secrets and your data access never reach the browser. The browser only holds a short-lived token.
Server only
- ONETWOAGENT_WIDGET_IDENTITY_SECRET
- Signs the identity exchange with OneTwoAgent. Never NEXT_PUBLIC_*.
- ONETWOAGENT_ACCOUNT_READ_CREDENTIAL
- Required on every account read from OneTwoAgent.
- @onetwoagent/integration/server
- Runs on the Node.js runtime. Bundling it into browser code fails with a clear error; on the edge runtime it fails at import with that instruction.
- Your account-data mapping
- Explicit, read-only projections. OneTwoAgent never writes to your app and never gets database access.
In the browser
- The widget script
- Loaded once with your public id from .onetwoagent.json — no secret in it.
- @onetwoagent/integration/browser
- Identify on sign-in, reset on sign-out, drop stale tokens when the user switches.
- A short-lived identity token
- Expires within 15 minutes; refreshed when the widget asks.
- Keep your auth, and keep these two routes out of browser-login redirects. The identity route checks the user’s existing session itself and returns 401 when nobody is signed in. The account route is called by OneTwoAgent server to server, without the user’s browser cookie, so middleware or a proxy must not send it to a sign-in page or demand a browser session; its handler still requires the read credential, a valid signed grant and a live session and membership check on every call.
- With a nonce-based Content-Security-Policy, the widget tag takes the page nonce; doctor checks your production CSP.
Sign-in, sign-out and everything in between.
The parts that usually break a support chat in a real app are handled by the package.
Sign in
identity.refresh()
The widget is told who the user is: identified.
Token runs out
otw:identity:required
The widget asks; identity.start() answers once per page.
Switch workspace
invalidate() → refresh()
The old identity is dropped before the new one is fetched.
Sign out
invalidate()
Runs before your sign-out request; the widget resets to anonymous.
Session ended elsewhere
403 reauth_required
Account reads stop at once, even with an unexpired grant.
Done when production says so.
A finished setup screen isn’t the finish line. Your coding agent ends with OneTwoAgent doctor against your live app.
What only a person can do — sign in once, ask one question — is reported as a manual check, never as a pass. Every problem has a stable code and a concrete fix, and --json gives your coding agent the same result.
$ npx -y @onetwoagent/cli@latest doctor --json --url https://app.example.com --wait 120
In your code and config
- The project connection and the installed skill
- Server env variables are set (names only, never values)
- Widget and identity wiring in your source
- No secret leaking into client code
- Your OneTwoAgent configuration and allowed domains
Against production
- The account route answers 401 without the read credential and 403 for a forged grant
- Your Content-Security-Policy, and the deployed HTML loads the widget
- The widget actually running, a signed-in identity, a signed-in conversation and live account reads
Tested in Next.js, end to end.
We keep two example Next.js 16.3 apps — App Router and Pages Router on Node.js 22 — built on the same package. Each passes 12 end-to-end checks against OneTwoAgent’s real token issuer and result parser, including:
- Signed out: the identity route answers 401 and calls nothing
- Signed in: a token that verifies for the right user and workspace
- Approved section and view read and accepted
- No credential: 401. Forged grant: 403
- After sign-out, the still-unexpired grant is refused
Your auth stays your auth.
Your server needs to know who is signed in, with a stable user id and an email. The coding agent maps the session your app already has — Auth.js / NextAuth, Clerk, Supabase Auth, Firebase Auth, JWT or cookie sessions — and never adds a second auth system. We don’t promise every provider works untouched: doctor confirms the signed-in path in your production.
Questions
Code on this page is abridged from the public package READMEs and the Next.js reference your coding agent uses. @onetwoagent/integration on npm · @onetwoagent/cli on npm · Next.js reference for coding agents
Does it work with the App Router and the Pages Router?
Yes. The App Router uses route handlers with createIdentityWebHandler and createAccountLookupWebHandler; the Pages Router uses API routes with createIdentityHandler and createAccountLookupHandler. The browser lifecycle and your mapping are the same in both.
Can the routes run on the edge runtime?
No. The server package uses Node.js crypto, so the routes declare export const runtime = 'nodejs'. On the edge runtime the server entry fails at import with that instruction instead of failing later.
Do I have to change how authentication works?
No. The identity route reads the session your app already has and returns the user id, email, name and the session row id. Your coding agent writes that mapping; it doesn’t install a second auth system.
Does OneTwoAgent write to my database?
No. The account route returns explicit, read-only projections you choose — the sections you approve and up to 8 support views — and checks your live session on every call. There is no direct database access.
Do I need to deploy on Vercel?
No. Your coding agent deploys the way your repository already deploys. On Vercel, one CLI command sets both secrets in production; elsewhere they go into your host’s production environment.
How long does it take?
It depends on your app — how sessions, workspaces and data are organized — so we don’t promise one number. The finish line is the same for everyone: doctor passing against your production.
What does it cost?
Plans are $19, $49, $99 or $249 a month, by AI conversations, with unlimited teammates on every plan. The 14-day trial includes 50 AI conversations and needs no card.
Put support inside your Next.js app.
Create your workspace, then connect your app from Install & Connect with your coding agent. 14-day free trial · 50 AI conversations · no card.
