There are four ways to put an AI assistant on a website, and what separates them is where the API key sits and who watches it. The simplest is a ready-made service that you paste into the site with a bit of code. The most flexible is a middleman of your own, on a server, that talks to the model. Either way, the key must never sit in the visitor’s browser.
The four options
| Option |
How it works |
Good for |
Watch out |
| Ready-made chat service |
A vendor gives you a snippet to paste into the site. It handles the model and the conversation. |
Starting fast, no server |
The conversation data passes through the vendor. Read their terms. |
| WordPress plugin |
A plugin connects the site to a model, with your key stored in the site. |
Anyone already on WordPress |
The key sits in the site’s database. Keep everything updated. |
| A middleman of your own |
The site asks your application, and the application calls the model with the key. |
Controlling what is said and spent |
It takes work, and the application becomes yours to maintain. |
| An automation flow |
A tool such as n8n receives the question by webhook, calls the model and replies. |
Linking the assistant to e-mail, spreadsheets and other services |
Needs a VPS. See what n8n is. |
How to choose
| 1 |
Define the assistant’s job. Answering frequent questions? Collecting quote requests? The narrower, the better it runs.
|
|
| 2 |
Decide where its knowledge comes from. From a text you put in its instructions, or from your documents. For the latter see RAG.
|
|
| 3 |
Pick the option by the job: a ready-made service to start, a plugin if you already have WordPress, a middleman of your own if you want control.
|
|
| 4 |
Set limits. A limit on messages per visitor and a spending limit at the provider. Without them, anyone who abuses the assistant spends your money.
|
|
| 5 |
Try difficult questions before you go live, including the ones it should not answer.
|
|
The site itself can stay on shared hosting, because the model provider does the thinking and the site only makes a call outward. What needs a VPS is a middleman that runs all the time, or a tool such as n8n. See shared hosting or VPS.
|
The assistant speaks for the company. If it invents a price, a deadline or a policy, the customer reads that as your promise. Tell it in its instructions to refer to a person when it does not know, and tell visitors they are talking to an AI. See AI hallucinations.
|
|
Personal data. What the visitor types is sent to an AI provider. Say so in the privacy policy and ask people not to type sensitive data. See data protection on your site.
|
|
Start with an assistant that only routes: it answers what is in the frequently asked questions and hands the rest to a person. It is the one that brings least risk.
|
|
Want to know where to put the middleman, on your hosting or on a VPS? Describe what you have in mind.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from 5.940,00 Kz/mo (3-year plan, with coupon) See plans |