Appearance
Xinbox AI customer support
Connect Packedge from Xinbox → Integrations → Native connectors → Packedge. You do not copy an API key. Packedge opens its consent screen: select your account and approve customer support capabilities. Only an account owner or administrator can approve.
Your Xinbox AI agent can help customers view their own orders, subscriptions, masked licenses and license activations; get permitted release downloads; and open checkout for public plans. Customers verify their purchase email using an emailed consent link before private account details are available. The verification grants access to the requesting conversation for 24 hours.
Subscription and license changes use a separate Packedge confirmation page. The agent prepares the link; the customer reviews and confirms the exact action. Stripe and Polar support cancellation at period end and resuming a scheduled cancellation. Other providers report unsupported actions. Activations can be deactivated after confirmation. Purchases finish in hosted checkout and are confirmed by payment processing.
Choose optional download, subscription, license and checkout permissions on the consent screen. Customer read access is required. Xinbox also lets you disable individual tools. Connecting or reconnecting does not merge customer profiles or authorize access to another customer's records.
Business reporting, other customers' purchases, processor credentials, private organization information, refunds and business administration are excluded. Order support includes the customer's own order amounts and receipt links.
Disconnect from Xinbox to revoke the installation. Packedge console consent revocation, removal of the approving member, or account suspension also stops access. Previously issued download links expire within ten minutes and require a valid license when used.
Support resource
The first-party OAuth client is xinbox-support, with resource /mcp/customer-support. Its credentials cannot authorize the business /mcp endpoint or developer API. Customer authorizations are sent by Xinbox servers in a separate per-call header; they are never model arguments.
Installation endpoints use support OAuth: GET/PUT/DELETE /v1/support/connection and POST /v1/support/customer/exchange. Product restrictions can be applied through PUT product_ids; an empty list allows all account products. Every private tool enforces installation, verified email, ownership and product restrictions.
