demo-platform/README.md
scot 9b09f14916 v0.1.0-alpha: interactive demo platform core
- Fastify API: demos/steps CRUD, content-addressed assets, scoped API keys
  (read/author/publish/admin, draft-only default per D4)
- Player: image + sandboxed DOM steps, hotspots, tooltips, keyboard nav,
  privacy-first beacons (no IP storage, viewer tokens only — R7)
- Editor: React SPA — demo list, drag-to-draw hotspots, annotations, publish
- MCP server: Streamable HTTP, scope-filtered tools, untrusted-data wrapping
  on viewer-supplied content (R8); platform never calls a model
- Capture extension (MV3): screenshot-flow recording, hotspots pre-placed
  from real clicks
- Docker: single app image + postgres, Traefik-ready (expose only)

E2E verified: capture->author->publish->play->beacon->lead->analytics + full
MCP tool surface with scope filtering.
2026-07-18 05:17:45 +00:00

55 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Demo Platform (working name)
Self-hosted, open-source interactive demo platform. One capture → interactive
clickable demo, step-by-step guide, narrated video. MIT licensed, built and
owned by DiligenceWorks Pte. Ltd.
**Status: v0.1 — early alpha.** Interactive demos (image steps) work end to end:
capture with the browser extension → refine in the editor → publish → share/embed.
## Why
The interactive-demo SaaS category (Arcade, Storylane, Navattic, Supademo) is
closed-source and $5001,200/mo, and your demos — unreleased UI, prospect
analytics, lead data — live in someone else's cloud. This runs on your
infrastructure. Nothing leaves it.
## AI without a bundled model
The platform **never calls an LLM**. It ships an **MCP server** (`POST /mcp`,
Streamable HTTP): attach your own agent — Claude, an IDE, your own runtime —
with a scoped API key, and it can list demos, write annotations, place
hotspots, reorder steps, read analytics, and (only with an explicitly granted
`publish` scope) publish. Draft-only by default; the human decides who may
publish. Viewer-supplied data (leads) is wrapped in untrusted-data markers.
## Quick start
```bash
docker compose up -d --build
docker compose logs app | grep -A2 "FIRST RUN" # your admin API key, shown once
```
Open `/editor`, paste the key. Create a demo, upload screenshots as steps (or
install `extension/` as an unpacked Chrome extension and record a real
click-through — hotspots are pre-placed from your actual clicks), drag hotspots,
write tooltips, publish. Share `/p/<token>`, embed with an `<iframe>`. Optional
viewer identification: append `?v=<viewer-token>` to the link you send.
## Privacy defaults
No IP addresses stored. No fingerprinting. Viewer identity only via explicit
share-link tokens. Lead deletion endpoint included.
## API scopes
`read` · `author` · `publish` · `admin` — keys default to `read,author`.
## Roadmap
DOM-fidelity capture (rrweb serialization, asset pipeline), step-guide export,
narrated video render, desktop capture agent. See DESIGN docs in the DW KB.
## License
MIT © 2026 DiligenceWorks Pte. Ltd.