| 开发者 |
glay
glayguo |
|---|---|
| 更新时间 | 2026年10月3日 21:06 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
[ai_chat_bedrock] shortcode or the chat block, or let it float on every page
from a single setting.
Three things this does differently
It runs without storing AWS keys. An instance role, a task role or environment variables are
enough. Off AWS, one Amazon Bedrock API key from the Bedrock console is all it takes to connect. Where keys are stored, they are encrypted, and Diagnostics generates the least-privilege
IAM policy this site actually needs rather than asking you to attach a broad managed policy.
It assumes a public chat will be abused. Every default below is the safe one, and each is a
setting you can change rather than a promise you have to trust:
[ai_chat_bedrock] to a page or post, or insert the chat block.wp-config.php instead:
define( 'AI_CHAT_BEDROCK_API_KEY', 'replace-with-bedrock-api-key' );
The plugin also reads AWS_BEARER_TOKEN_BEDROCK, the variable the AWS SDKs use. An API key covers chat, streaming, the model list and embeddings. Knowledge Bases, reranking, Prompt Management and AgentCore Gateway do not accept API keys, so they still need an IAM role or access keys, and Diagnostics says so when one of them is configured. Short-term keys expire after at most 12 hours, which suits a test but not a live site.
Minimal IAM policy
Replace REGION and MODEL_ID with your own values. Inference profiles and some model types use different resource ARNs; follow the AWS documentation for the model you select.
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "bedrock:InvokeModel", "Resource": "arn:aws:bedrock:REGION::foundation-model/MODEL_ID" } ] }
Keeping credentials out of the database
For stronger isolation, define credentials in wp-config.php instead of saving them in the WordPress database:
define( 'AI_CHAT_BEDROCK_AWS_ACCESS_KEY', 'replace-with-access-key' );
define( 'AI_CHAT_BEDROCK_AWS_SECRET_KEY', 'replace-with-secret-key' );
define( 'AI_CHAT_BEDROCK_AWS_SESSION_TOKEN', 'replace-with-session-token' ); // Optional.
Credentials saved through the settings screen are encrypted with authenticated encryption derived from the site's WordPress authentication salts, and saved secrets are never rendered back into the form.Run AI Chat Bedrock > Diagnostics first: most problems are a missing IAM permission or model access, and it names which. Then ask in the support forum, without posting keys. Longer answers are in the detailed FAQ.
No. Model requests use Amazon Bedrock and your AWS credentials. Availability, model access, pricing, and data handling are governed by your AWS account and Region.
Yes, in the Live Preview on the plugin's WordPress.org page, which runs WordPress in your browser with demo mode on. The chat then quotes the passage of the site's pages that best matches each question, and says that no AI model was called. Demo mode is off unless AI_CHAT_BEDROCK_DEMO is defined, and ends once AWS credentials are found.
Claude, Amazon Nova and Titan, Meta Llama, Mistral, DeepSeek and the other chat models your Region offers, including Claude Sonnet 5, Claude Opus 5.5 and Claude Haiku 4.5; Stability AI models for images; Cohere Rerank 3.5 and Amazon Rerank 1.0 for reranking. The settings screen lists what your account offers, and a new installation starts on Amazon Nova Lite. Regions, inference profiles and image models.
It is a single credential created in the Amazon Bedrock console and sent as a bearer token, so there is no IAM user or access key pair to manage. It is the quickest way to get a first answer, especially on hosting outside AWS. On an EC2 instance, ECS or EKS an IAM role is still the better choice, because nothing long-lived is stored at all. If a key stops working, check that it has not expired or been revoked and that its identity is allowed bedrock:CallWithBearerToken; the IAM policy that Diagnostics generates includes it when a key is configured.
Yes, on Claude 3.5 Haiku, Claude 3.7 Sonnet and newer Claude models, which Bedrock supports it for. The site's system prompt and tool definitions are the same for every visitor, so they are marked for Bedrock's prompt cache; a later request that starts the same way reads them at a fraction of the input price. Writing to the cache costs slightly more than a normal input token, and a prompt shorter than the model's minimum is simply not cached, so a site with a short prompt pays what it paid before. The dashboard and wp ai-chat-bedrock usage show cache reads and writes. The ai_chat_bedrock_prompt_caching filter turns it off.
Amazon Bedrock no longer has a Model access page: a model is turned on for the AWS account the first time it is called. That first call fails when the identity may not subscribe through AWS Marketplace, when the account has no payment method, or, for Anthropic models, before the one-time use case form is submitted. Opening the model once in the Bedrock console playground as an administrator settles all three, and the chat's error names which one it was. Otherwise, check the model ID, whether it needs an inference profile ID, and that the identity can call bedrock:InvokeModel on it.
Yes, with Polylang or WPML. The chat title, welcome message and suggested questions are listed for translation under "AI Chat for Amazon Bedrock" in Languages > Translations (Polylang) or String Translation (WPML), including those of each profile, and each edition of the site shows its own. Answers are asked for in the language of the page, and with Polylang are drawn from pages in that language first. Keep the system prompt in one language; it is not translated. The chat's own buttons and notices, and the plugin's admin screens, come in Simplified Chinese and Japanese with the plugin, and in other languages once translate.wordpress.org has them.
The chat defaults to signed-in users to reduce the risk of anonymous scripts generating unbounded AWS charges. Guests see a sign-in link that brings them back to the same page; the ai_chat_bedrock_sign_in_url filter can point it at a custom sign-in page, or hide the chat from guests by returning an empty string. An administrator can explicitly enable guest access and configure a request limit.
Newly saved credentials are encrypted with authenticated encryption derived from WordPress salts. Existing plaintext credentials are migrated when an administrator opens the dashboard. wp-config.php constants remain the preferred production option.
Yes. Configure the access key, secret key, and session token together, or define all three constants in wp-config.php. A short-term Amazon Bedrock API key also works, and Diagnostics warns that it expires within 12 hours.
Yes. Streaming is the default and uses an authenticated POST request with Server-Sent Events. The removed 1.0.x implementation was unsafe because it used a GET EventSource that placed conversation data in URLs and issued duplicate Bedrock requests. If the PHP cURL extension is missing or a proxy buffers the stream, the chat falls back to one buffered request automatically.
Yes. Leave the key fields empty and keep IAM role credentials enabled. The plugin then uses server environment variables, an ECS or EKS task role, or the EC2 instance role through IMDSv2.
HTTPS and WordPress safe HTTP validation reduce server-side request forgery risk and protect tool inputs in transit. Private, loopback, link-local, credential-bearing, and unsafe redirect targets are rejected.
It is read-only and returns published content only. WordPress authentication is required by default. Administrators may explicitly expose it publicly; public requests are then rate limited.
Yes. The model can call tools, read the results, and continue reasoning for up to the configured number of rounds, defaulting to 3. The last round is answered without tools so the conversation always terminates. Tool output is always framed as untrusted data.
Not by default. The built-in WordPress MCP endpoint is read-only. For external MCP servers, any tool that looks like it changes data is blocked until an administrator allows it, and those tools stay restricted to administrators.
No. This plugin does not send plugin-usage telemetry to the plugin author. Requests are sent only to services the administrator configures, as described in the Data flow and privacy section.
No. Amazon Bedrock and AWS are trademarks of Amazon.com, Inc. or its affiliates. This is an independent open-source WordPress plugin.
Each message is one authenticated POST to a plugin REST route, relayed to the browser with Server-Sent Events, with a buffered fallback when PHP cURL is unavailable. Credentials come from an API key, wp-config.php constants, encrypted settings, environment variables, an ECS or EKS task role, or an EC2 instance role, in that order; Diagnostics shows which one is used. The full order and caching.
An authenticated conversation can call tools from an MCP server an administrator configured. A capability is required (edit_posts by default), tools that change data stay blocked until allowed, rounds are capped, and every call is audited without its values. How the policy works.
Yes. Point the chat at a prompt in Bedrock Prompt Management, pinned to a version or following the draft; the local prompt is used if it cannot be read. Placeholders and caching.
Choose an embedding model and questions are matched by meaning, not shared words, over published content as a signed-out visitor sees it. Vectors live in the WordPress database or, for a larger site, in Amazon S3 Vectors in your AWS account. Indexing, S3 Vectors, filters and languages.
A reranking model scores up to eight passages from site content and the knowledge base against the question and keeps only the best. It is one extra request per question, shown apart on the dashboard, and the passages are used as before if it fails. Thresholds and IAM.
Turn on Show sources under Answer grounding and up to three links are listed under each answer, to the published pages and knowledge base documents it was given. Pages that only share a single word with the question are not listed.
The Fixes for other plugins tab has small, optional adjustments for FluentAuth, Polylang and Yoast SEO. Each is off until you turn it on, and does nothing while the plugin it adjusts is inactive: read-only GitHub sign-in, social-only registration, an hreflang x-default for search engines, and crediting articles to the organization in Yoast's structured data.
Behind a load balancer or CDN every guest arrives from the proxy's address. If you control the proxy, return the address it reports from the ai_chat_bedrock_client_ip filter, for example CloudFront's CloudFront-Viewer-Address header. Never use a header a visitor can set directly, such as an unverified X-Forwarded-For, or anyone can escape the limit by sending a new value each time.
Model access is the most common reason a Bedrock chat stops answering: a model is not enabled, throttled, or briefly unreachable. Choose a fallback model and those requests are retried once on it, and the reply states which model answered. An unrecognized identifier is treated the same way; requests rejected for any other reason are never retried. A stream is retried only before anything reaches the browser.
The chat is a self-contained, responsive interface with message bubbles, a typing indicator, a live streaming caret, tool activity status and per-answer token counts. Answers can be copied, failed requests can be retried, and every message carries a timestamp. It follows dark-mode and reduced-motion preferences and keeps focus styles and screen-reader labels intact. Add up to four suggested questions and they appear as buttons above the input, disappear once the conversation starts and return when the chat is cleared. When the conversation log is enabled, each answer also gets a discreet Was this helpful? control; only the rating is stored, never anything about the visitor.
Yes, under Chat > Conversation memory, which is off by default so every page starts a new conversation. Keep it while the visitor browses stores the conversation in the browser tab's session storage: it follows the visitor from page to page and is gone when the tab closes, and nothing is stored on the site. Also save it for signed-in visitors keeps a signed-in visitor's last 30 messages per chat on the site, so the conversation is there on their next visit and on another device. Saved messages are deleted after the days you set (30 by default), when the visitor clears the chat, through Tools > Erase Personal Data, and all at once when you switch the option off. Guests only ever get the browser-tab memory. Add the suggested text from Settings > Privacy to your privacy policy before turning saving on.
Yes, with Amazon Polly, off by default: a Listen button under chat answers and one above posts, in a voice for the page's language. Post audio is saved once and reused. New audio has a daily limit for the site and for each visitor, crawlers cannot have posts read, and posts can be kept for signed-in visitors. Voices, costs and filters.
Yes, under Chat > Contact requests, off by default. A Contact a person button below the chat opens a short form, and the assistant points to it when it cannot help. Requests need consent and are listed under Contact requests; Akismet, Flamingo and Joinchat are used when present. Spam checks, email and hooks.
Yes, under Chat > Analytics events, off by default. Opens, questions, answers, followed sources and products, ratings and contact requests go to Site Kit, MonsterInsights, Google Tag Manager, Matomo or Plausible, without message text, and wait for statistics consent where the WP Consent API is used. Events and parameters.
Any chat can render as a floating button instead of an inline panel:
[ai_chat_bedrock mode="popup" launcher="Ask us" profile="support"]
A site-wide floating chat can be enabled with its own profile. Pages that already contain the chat block or shortcode are left unchanged, so the chat is never duplicated. The launcher is keyboard accessible, closes with Escape, stays open while a visitor browses other pages in the same tab, and adapts to small screens.
One installation serves several chats. Each profile has its own key and can override the model, system prompt, title, welcome message, suggested questions, token limit, temperature, request limit, guest access, grounding and passage count. Anything left empty inherits the main settings.
[ai_chat_bedrock profile="support"]
Profile keys arriving from a page, block or chat request are validated against the stored profiles, so an unknown or crafted key falls back to the main settings and can never unlock guest access. Requests are rate limited per profile, and up to ten profiles can be stored.
All content tools are optional, require the capability to edit the item, and are rate limited.
On WordPress 7.0 and later, Bedrock is registered with core's AI Client, so wp_ai_client_prompt() reaches it from any plugin that knows nothing about AWS. Those calls use this plugin's request path, so the guardrail, model, region, token ceiling, daily limit and usage accounting configured here apply to them.
On 7.1 and later, Amazon Bedrock also appears under Settings > Connectors. On AWS it shows as connected with nothing entered, because the IAM role is used. Elsewhere, paste an Amazon Bedrock API key there: it is checked with Bedrock before it is kept, and stored encrypted. A key in the plugin settings or wp-config.php takes precedence.
Core asks for a model by what it must do, and the plugin describes each Bedrock model truthfully: image input only on models that read images, image generation only on the Stability models, and embeddings only on WordPress 7.2 and later. More on model capabilities.
Yes, once you choose an image model on the Model tab. Plugins that use the WordPress AI Client can then generate images, and with the media helpers on, the Media Library offers Remove background and Upscale 4× on each image. Edits are saved as new images. A prompt is checked with your guardrail first, because Bedrock Guardrails headers do not apply to image models, and an image the model filtered is reported rather than saved. Each image is a billed request to Stability AI on Amazon Bedrock, counted against the daily limit. The IAM policy in Diagnostics includes the image models you turned on.
Point the client at https://example.com/wp-json/ai-chat-bedrock/v1/mcp and sign in with a WordPress Application Password over HTTPS, or turn on OAuth 2.1 so the client connects by signing in and approving, with no password copied. Every tool call is capability-checked and audited; anonymous access and OAuth are off by default. Protocol revisions, tools and OAuth details.
External servers are called with JSON-RPC over Streamable HTTP with a declared protocol version. Three authentication modes are available:
bedrock-agentcore and the region falls back to the Bedrock region.With Product answers on, the facts of up to four matching products (eight at most, set under WooCommerce) are sent with the question: name, link, SKU, price, stock, rating, categories, visible attributes, options and a short description, exactly as the shop shows them to any visitor. With Order questions on, a signed-in customer's question about orders or delivery adds their five most recent orders, plus any they name by number that are theirs: order number, dates, status, items, total, shipping method, tracking number and the link to the order page. Billing and shipping addresses, email, phone, payment details and customer notes are never read into the prompt. A question that is not about orders sends no order data, and a visitor who is not signed in is asked to sign in. Add the suggested text from Settings > Privacy to your privacy policy before turning Order questions on. The ai_chat_bedrock_woocommerce_products, ai_chat_bedrock_woocommerce_product_facts, ai_chat_bedrock_woocommerce_orders and ai_chat_bedrock_woocommerce_order_lines filters adjust what is sent.
Only products any visitor can see are described: published, without a password, visible in the catalog or in search, and in stock when WooCommerce is set to hide out-of-stock items. A SKU in the question, such as "is ARM-6 in stock?", finds that product directly. Otherwise products are found by name and description, then by category, and a follow-up such as "how much is it?" searches with the previous question. The ai_chat_bedrock_woocommerce_listable filter can leave out more products.
With site abilities on (off by default), agents can search and read published posts and pages, get SEO suggestions without saving, look up published products and create a draft. Nothing is published, updated or deleted, and orders and customers are never exposed. The abilities are in WordPress's own registry, so the official MCP adapter and /wp-abilities/v1/ see them too. How the declared behaviour is enforced.
Turn on Site description and agents get a describe-site ability listing what the site holds as schema.org types, with counts per language, how the types relate and a sensitivity class for each property. IDs match the ones Yoast SEO and WooCommerce print in the page. Sensitivity rules and single-item descriptions.
Turn on Business insights under Answer grounding. Editors see content figures, administrators also see AI usage and question figures, and store figures need the WooCommerce reports capability. Store figures come from WooCommerce Analytics with its status and date settings. Any figure counted from fewer than five orders or questions is withheld, together with one more where it could be worked out from the total. Agents get the same figures through the query-metrics ability and MCP tool, except those about visitors' questions.
wp ai-chat-bedrock index builds the semantic index without keeping a browser tab open, with --batch, --max and --force. index-status reports coverage, diagnose runs the same checks as the admin screen with an optional --live Bedrock request, and usage prints requests and tokens per day or per model. Useful in a deploy step or a cron job.
Write questions with expectations, then run wp ai-chat-bedrock eval. Each goes through the
pipeline the chat uses; results are reported by category: grounding, match strength, citation,
required and forbidden text, tool call, token budget. It exits nonzero to gate a deployment, and
--compare shows the per-category difference after a change.
Every check is a program, not an opinion: no judge model, no scoring of style, and anything
not checkable this way is reported as unchecked rather than as a pass.
The Answer checks screen edits and runs the set, and proposes cases from questions the site was
asked and answered badly. A proposal carries the question, never the expectation: no record holds
what a good answer says.
ai_chat_bedrock_lead_captured passes them on. Joinchat's WhatsApp number is offered as another way to reach the site.AI_CHAT_BEDROCK_DEMO is defined and no AWS credentials are found, the chat quotes the passage of the site's pages that best matches each question and says that no AI model was called.ai_chat_contact as a key event to count contact requests as conversions.wp-config.php still takes precedence.ai_chat_bedrock_review_prompt filter turns it off.