1. Docs
  2. Guides

AI actions

AI actions let the AI assistant — and your teammates, with one click — look things up and get things done for customers: invoices, services, domains, WooCommerce orders, EPP codes, nameserver changes, reboots, coupons, refunds, and anything your own systems can do over HTTPS.

How it works

  1. A customer asks, for example, “Do I have unpaid invoices?”. The AI says what it is doing and requests the Invoices action.
  2. If the conversation is not verified yet, the customer is asked to confirm it’s them first (Customer verification). The AI continues on its own once they did.
  3. Actions that only read run at once. Actions that change something wait for a teammate: an Approve & run / Reject bar appears in the conversation, with an inbox notification and push for those who may approve. Rejecting hands the conversation to the team.
  4. The result goes back to the AI, which answers the customer — with the pay link, the EPP code, the new nameservers…

What is available

  • WHMCS (module 1.1+): invoices, invoice payment link, services, domains, domain nameservers, support tickets; and — once you allow them in the module — EPP codes, nameserver changes, server reboots and password-reset emails.
  • WooCommerce (WordPress plugin 1.2+): orders, order details (with tracking), product search; and — once allowed in the plugin — personal coupons, cancellations and refunds (recorded in WooCommerce, no money is moved by the payment gateway).
  • Your own actions: any HTTPS endpoint (below).

Who may do what

In Settings → AI actions switch Let the AI use actions on and choose, per action:

  • AI: Off · Runs on its own · Asks a teammate (default for anything that changes something).
  • Teammates: All teammates · Admins only (default for changes) · Nobody. This also decides who may approve the AI’s requests.

The WHMCS module and WordPress plugin decide what is possible at all: actions that change something are off there until you switch them on. Account actions always use the verified email; teammates can read with the contact’s email but need a verified conversation to change anything (or run it as a test).

Test mode simulates every change (a dry run): the module, plugin or your endpoint describes what would happen and changes nothing. Use it while you try things out.

The activity log

Every run — by the AI, a teammate or the Try an action console — is listed in Settings → AI actions with who ran it, who approved it, the customer and the result, and appears in the conversation timeline. EPP codes, tokens and sign-in links are kept out of the log. The action.run webhook reports each run.

Your own actions

Add one under Settings → AI actions → Your own actions: a name, a sentence telling the AI when to use it, the URL (HTTPS), optional headers (stored encrypted) and up to four arguments. We send:

HTTP
POST https://api.example.com/talkingdot/license
Content-Type: application/json
X-TalkingDot-Timestamp: 1791234567
X-TalkingDot-Signature: v1=5f2b…   (HMAC-SHA256 of "{timestamp}.{body}" with the action's signing secret)

{"action":"check_license","email":"jane@example.com","args":{"license_key":"LIC-9"},"dry_run":false,
 "actor":"ai","agent_name":"Nova","conversation":123,"request_id":"9f1c…","workspace":"Acme"}

Answer with JSON. summary is what people see; everything else goes to the AI as data:

JSON
{"ok": true, "summary": "License LIC-9 is active until 2027-01-31", "license": {"status": "active", "expires": "2027-01-31"}}
{"ok": false, "error": "No license for this email"}

Check the signature and reject requests older than five minutes. With GET, everything is sent in the query string. A repeated request_id is the same request — don’t do it twice.

Last updated October 5, 2026 Something unclear? Tell us