- CategoryEcommerce
- AuthConsumer key + secret
Overview
WooCommerce connects on /integrations in the dashboard. Click the WooCommerce card and the 'Connect to WooCommerce' modal opens with three fields: Store URL, Consumer Key and Consumer Secret. The key pair is a WooCommerce REST API key the merchant generates in WordPress under WooCommerce, Settings, Advanced, REST API, Add key, with permissions set to Read/Write. MessageMind sends the key as query parameters on every call to the wc/v3 namespace. At save time MessageMind runs a read probe AND a safe write probe against a non-existent product id so a Read-only key pair is refused up front, before it would silently break product sync, coupon creation and order status changes further down the line. Once the key passes, the integration is enabled; product sync is a separate per-store toggle and assistant ordering (quote and create an unpaid order on the shopper's behalf) is a per-tenant opt-in that stays off by default.
What MessageMind can do with it
- Validate the merchant's REST key pair at connect time with a read AND a write probe, so a Read-only key is refused before it breaks product sync, coupon creation or order actions.
- Read the product catalog from wc/v3/products so the AI can quote prices and attributes in-thread.
- Look up a customer's past orders by email or phone to answer purchase-history questions and feed the 'Customer purchased' automation condition.
- Create a one-time coupon on the merchant's store from the 'Create Woo Coupon' automation action.
- Change the status of an existing order from the 'Change Order Status' automation action.
- Receive orders.created, orders.updated and products.created / updated / deleted webhooks so the AI's view of the store stays current.
- Optionally quote and create an unpaid order on the shopper's behalf (two-step quoteWooOrder then createWooOrder) and hand them the store's own pay link; the AI never takes payment.
Requirements
- A WooCommerce store on WordPress, reachable over HTTPS, with the REST API enabled and permalinks set to something other than Plain.
- A WooCommerce REST API key pair with Read/Write permissions, generated under WooCommerce, Settings, Advanced, REST API.
- Optional, needed only for assistant ordering: at least one payment gateway enabled on the store for the currency being quoted.
How to connect
- In WordPress, open WooCommerce, Settings, Advanced, REST API and click Add key. Set Permissions to Read/Write and generate the key. WordPress shows the Consumer Key and Consumer Secret only once; copy them straight away.
- In the MessageMind dashboard, open /integrations and click the WooCommerce card. The 'Connect to WooCommerce' modal opens.
- Fill in the three fields: Store URL (for example https://yourstorename.com), Consumer Key and Consumer Secret.
- Click save. MessageMind proves the key with a read against the store AND a safe write probe against a non-existent product id. If the key is Read-only, the connect is refused with a message asking you to recreate it as Read/Write.
- Once validated, the integration is marked Enabled. Toggle product sync on from the integration page to register the orders.* and products.* webhooks on the store.
Authentication and permissions
- Mechanism
- WooCommerce REST API Consumer Key and Consumer Secret (keyed REST, not OAuth), sent as consumer_key and consumer_secret query parameters on every call to the wc/v3 namespace. Inbound webhooks are verified with a per-tenant signing secret minted at connect time.
- Credentials
- Three fields in the connect form: Store URL, Consumer Key and Consumer Secret. A webhook signing secret is stored on your tenant alongside them.
Available data and actions
Reads
- Products and variations from wc/v3/products.
- Orders from wc/v3/orders, searchable by customer email or phone, used for the purchase-history condition.
- Order statuses and store base currency, needed to validate automation steps and assistant-ordering quotes.
- Store configuration used by assistant ordering (base currency, shipping zones, available payment methods) through the WooCommerce Store API when enabled.
Writes
- Coupons created through wc/v3/coupons from the 'Create Woo Coupon' automation action.
- Order status transitions through PUT wc/v3/orders/{id} from the 'Change Order Status' automation action.
- Unpaid orders created through wc/v3/orders at status pending and signed with messagemind_source, messagemind_origin and an HMAC signature so the merchant can identify and verify them. Only when assistantOrders is enabled on the tenant.
- Webhook subscriptions on the store itself, created and removed through wc/v3/webhooks when product sync is toggled.
AI agent use cases
- A shopper asks for a discount; an automation creates a one-time coupon on the store and the AI hands the code back in-thread.
- A shopper asks about a past purchase; the AI searches the store by their email or phone and quotes the matching orders.
- An automation changes an order's status (for example, to on-hold) in response to a conversation event.
- When assistant ordering is enabled, the shopper describes a basket, the AI quotes it live against the store (resolving products, delivery options and totals) and, on confirmation, creates ONE unpaid order and returns the store's pay link.
Configuration
- Product sync is per-store and off by default; turning it on registers the orders.* and products.* webhooks on the store.
- Assistant ordering is per-tenant through integration.settings.assistantOrders and off by default.
- assistantOrderExpiryMinutes sets how long an unpaid assistant order stays open before MessageMind's sweep cancels it on the store (default 60 minutes).
Example workflows
Quote and pay inside a chat thread (assistant ordering, opt-in)
- The shopper describes the basket to the AI.
- The AI calls quoteWooOrder, which resolves products against the live store, prices delivery options and returns a quote per option with its own quoteId and totals.
- The shopper picks a delivery option and confirms.
- The AI calls createWooOrder with that quoteId; MessageMind creates ONE unpaid order in the store signed as an assistant order.
- The AI shares the store's own payment link. The customer pays on the store; the store sends its usual post-payment emails.
Limitations
- A Read-only key pair cannot run product sync, coupon creation, order-status changes or assistant ordering. The connect probe refuses it on purpose rather than letting it fail later.
- WordPress core routes (wp/v2) cannot be reached with a WooCommerce REST key alone; a WordPress Application Password is required for those.
- Assistant ordering has its own guardrails: coupons are refused when any line in the basket is synthetic, and a basket must contain at least one real product line.
- If permalinks are set to Plain, the WooCommerce REST API is unreachable and the connect probe will fail.
Troubleshooting
Connect fails with 'Those keys are Read only'.
Recreate the WooCommerce REST key under WooCommerce, Settings, Advanced, REST API with Permissions set to Read/Write. A Read-only pair cannot create coupons, change order status or run product sync, so MessageMind refuses it at connect time.
Connect fails with 'No WooCommerce REST API was found'.
Confirm the Store URL is correct, that WooCommerce is installed and that WordPress permalinks are not set to Plain. The REST API is unreachable under Plain permalinks.
An assistant order's pay page shows no payment methods.
Confirm the quoted currency matches a currency the store actually sells in and that at least one payment gateway is enabled for that currency on the store.
Disconnect and reconnect
- In the MessageMind dashboard, open /integrations, click the WooCommerce card and choose Disconnect. The stored Store URL, Consumer Key, Consumer Secret and webhook signing secret are removed from your tenant, and MessageMind removes the orders.* and products.* webhooks it registered on the store on a best-effort pass with the current credential.
- In WordPress, delete the REST API key under WooCommerce, Settings, Advanced, REST API to revoke it on the store side as well.
- To reconnect, create a fresh Read/Write key in WordPress and paste it into the WooCommerce card. Previously created coupons and orders stay on the store; disconnecting does not remove them.