# Build brief — a focused alternative to MagicChat

> **Verdict:** Partly, if you narrow it · **Buildability:** 49/100 · **Category:** Customer Support
> **Source:** https://www.canitbevibecoded.com/magicchat
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from MagicChat. Verify current pricing and capabilities before acting.

## Context

**MagicChat** — Train an AI support chatbot on your own content and embed it on your site. It currently costs $59/mo.

A retrieval chatbot over your own docs is one of the most one-shottable products there is: crawl the site, chunk and embed it, answer from the top matches with an LLM, drop in a widget. What you don't get for free is the boring operational layer, scheduled re-crawls, analytics, lead capture and human handoff, multi-source connectors, and a hosted widget that stays up. Buildable in a focused implementation, real gaps after that.

This brief describes a focused, single-operator replacement for the part of MagicChat that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Crawl a site or docs, chunk and embed the pages into a vector store, retrieve the top matches for a visitor question, and answer with an LLM through an embeddable chat widget.

- Triage a shared inbox, draft replies from stored context, and track resolution state.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- An embeddings model.
- A vector store (pgvector or sqlite-vec).
- A public HTTPS deployment for the widget.

### Data and integrations

- OpenAI/Anthropic API key.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me an AI support chatbot that trains on my own website and docs, to replace
MagicChat, in an empty repo.

Stack (no alternatives): Next.js 15 (App Router) + TypeScript, Postgres with the
pgvector extension via Drizzle ORM, and Docker Compose so `docker compose up` runs
Postgres and the app together. Use the OpenAI or Anthropic API for both embeddings
and answers (keys in .env).

Core loop:
- `npm run ingest -- <sitemap-or-url>`: crawl the pages, strip to clean text, chunk
  (~800 tokens with overlap), embed each chunk, and store text + vector + source URL
  in Postgres.
- A /api/chat route: embed the incoming question, pull the top-k chunks by cosine
  similarity, and ask the LLM to answer ONLY from that context, returning the source
  URLs it used. Stream the answer.
- A single embeddable widget: one <script> tag mounts a floating chat bubble on any
  site, talking to /api/chat with CORS locked to configured origins.

Details:
- One config file: bot name, greeting, allowed origins, model, top-k.
- Store everything locally in Postgres; `npm run reindex` re-crawls and replaces.
- Secrets in .env, ship .env.example, never commit keys.
- Handle empty, loading, and "I don't know from the docs" states honestly; never
  invent answers outside the retrieved context.
- Out of scope: multi-channel (email/WhatsApp/Slack), team seats, an analytics
  dashboard, human handoff, scheduled auto-refresh (leave a documented cron hook),
  and any hosted control plane.
- README: setup, the ingest command, embedding the widget, and where data lives.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Scheduled auto re-crawl and content refresh.
- Analytics and conversation-history dashboards.
- Lead capture and human handoff.
- Multi-source connectors and integrations.
- Hosted uptime for the widget.
- Team seats and enterprise compliance (HIPAA/DPA/BAA).

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: medium. No reviewed project implementation is linked yet.

## Existing alternatives

Before building, compare these checked options:

- [Onyx](https://www.onyx.app) — Self-hosted chat over your own docs with connectors and permissions; heavier to run than a widget, but the whole RAG loop is yours

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [Onyx (formerly Danswer)](https://github.com/onyx-dot-app/onyx) — Open-source AI assistant that answers questions over your own documents
- [Flowise](https://github.com/FlowiseAI/Flowise) — Open-source builder for RAG chatbots you can embed

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/magicchat
