luckpanda
Chatbot use case

Let the chatbot look up the answer in your own system

Some questions have no answer on any page: where is my order, is this in stock, which plan am I on. Connect a read-only API or MCP server, and the chatbot asks the visitor for what it needs, calls your system and answers with what came back.

No account needed to try it. We read the public pages of your site, build the chatbot in about a minute and delete it after 7 days unless you keep it.

  • Read-only by default
  • Credentials encrypted, never shown to the model
  • Every call logged
The gap

Questions no page can answer

Your website says how long delivery usually takes. It cannot say where one customer's parcel is today.

Your pages can answer

  • How long delivery usually takes
  • Which sizes a product comes in
  • What each plan includes
  • Which services you offer, and when

Only your system can answer

  • Where this customer's order is today
  • Whether the large size is in stock right now
  • When this account's plan renews
  • Which slots are still free on Thursday

A connection closes that gap for questions that only need reading. The bot can tell a visitor which slots are free, for example; making the booking stays on your booking page.

Sample conversation

Where is my order, answered in the chat

Sample conversation on a fictional spice shop's website, with an order-status connection

Where is my order? I ordered on Monday.
I can check that for you. What is your order number, and the email you ordered with?
SK-20418, priya@example.com
Order SK-20418 shipped on Tuesday, and the latest tracking update says it is out for delivery in Jaipur today.
Called api_order_status
Can I add one more packet of garam masala to it?
An order cannot be changed once it has shipped. You can place a new order, and orders over ₹499 ship free. Would you like me to pass this chat to the team in case they can help?
Searched knowledge: change order after shipping
From the page: Orders and changes

The bot asked for two values because the shop's API needs both. It read the order and did not try to change it. The connection is read-only, so it could not.

Setting up

What an HTTP connection needs

A handful of fields. The bot sees the name and the description, never the credential.

FieldWhat to enterExample
NameWhat the connection is, in a few wordsOrder status
URL templateYour endpoint, with each value the bot must ask for in braceshttps://api.yourshop.example/orders/{order_id}?email={email}
Read-onlyTicked by default, which means GET requests onlyTicked
Auth headerThe header name your API expects, and its valueX-Api-Key, with your key as the value
DescriptionWhat it returns and when the bot should use itReturns status and tracking for one order. Use when a customer asks where their order is.

Each {name} in the URL becomes a value the bot asks the visitor for. Values are URL-encoded and limited to 200 characters. A call times out after 8 seconds, and at most 8,000 characters of the response reach the model.

Two ways to connect

An API you already have, or an MCP server

HTTP API

  • One endpoint per connection, up to 10 connections per bot
  • GET by default; POST with a JSON body only if you untick Read-only
  • Test connection makes one call with sample values and shows the status, timing and a preview of the response

Remote MCP server

  • Its Streamable HTTP address, and an auth header if it needs one
  • Test connection lists the tools the server offers
  • While Read-only is ticked, only tools the server marks read-only are offered, and an allow-list can narrow them further

Start with the question behind your most common "please check for me" email. One connection that answers it well is worth more than five the bot rarely uses.

Who sees what

Let your API decide what a visitor may see

The chatbot does not sign visitors in. Anyone can type an order number into a chat, so the check belongs in your API. Ask for two values, such as the order number and the email or phone on the order, and return the order only when they match.

Return only the fields a customer should see. Leave out internal notes, costs and other customers' details, because whatever your API returns can be used in the reply.

  • Read-only by default: HTTP GET, and MCP tools the server marks read-only
  • Credentials encrypted at rest and never shown again: not to you, not to API clients, not to the model
  • Addresses on private networks are refused, and every redirect is checked again
  • Every call is logged with time, request, result, status code and duration, never the credential
Before visitors use it

Test it the way a customer would

  1. Run Test connectionUse a real order number. Check the status code, and that the preview shows what you expect.
  2. Ask in the test chatWrite the question as a customer would. Under the reply you see which connection the bot called.
  3. Try the wrong valuesGive a real order number with the wrong email. The bot should say it could not find the order, not show someone else's.
  4. Read the call logFailed calls show the error. If the bot calls a connection for the wrong questions, make its description more specific.

If you untick Read-only, the bot may send POST requests or call MCP tools that change data, and there is no step yet where a person approves each call. Keep connections read-only unless you are sure.

Questions

Do I need to build an API?

You need an endpoint on the public internet that returns the data, or a remote MCP server. If your shop or booking system already has an API, a developer can point a connection at it or put a small endpoint in front of it. There are no ready-made connectors for named platforms.

Can the bot change an order or take a payment?

Not with a read-only connection, which is the default. It never takes payments. If you untick Read-only it may send POST requests or call MCP tools that change data, without a per-call approval step, so only do that for actions you are happy to let it take.

Does the model see my API key?

No. The key is stored encrypted and added to the request by LuckPanda. It is redacted from previews and logs, even if your API echoes it back. The model sees the connection's name, its description and the response.

What happens if my API is slow or down?

Each call waits up to 8 seconds. If it fails, the bot gets an error instead of data and is told not to show raw errors to the visitor. The failed call appears in the call log with the reason.

Can it reach a server on my office network?

No. Localhost, internal host names and private network addresses are refused, including when a public name points to one. The endpoint must be reachable from the internet.

Is this included in the price?

Yes. Connections are free to set up and test. On your website they work once the bot is live on the Chatbot plan, ₹249 a month for up to 10 websites, with no charge per call.

For AI agents

Build it with your AI agent

Give an agent your site and it can create the chatbot, read your pages and test it through LuckPanda's API and MCP. It prepares the work; going live stays with you.

Use LuckPanda's MCP server (https://luckpanda.app/mcp) to build a website chatbot for me. Ask for my website address, call chatbot_create_from_website with it, wait until the pages are learned (chatbot_source_list), then run a few test questions with chatbot_test_message and show me the answers. Do not put it live: I will do that myself.

Instructions for AI agents

Needs a LuckPanda agent key (Settings › Developers) with the chatbot.manage grant. MCP endpoint: https://luckpanda.app/mcp (Streamable HTTP, bearer key).

  • chatbot_create_from_website { url }: creates a draft chatbot named after the site and starts reading it.
  • chatbot_source_list: pages learned, failed or skipped, with a reason for each.
  • chatbot_test_message: asks the bot a question as the owner. Test chats never email anyone.
  • Going live (chatbot_update with status live) is a person's action; an agent gets APPROVAL_REQUIRED.

See it on your own website

Paste your address and watch the chatbot learn your pages. No account and no card.