AgentShoppable

Description

AI shopping agents are starting to browse and buy on their own. They do not see your store the way a person does: they read your catalog, your structured data and your policy pages, and they give up quietly when something does not answer the way they expect. The store owner sees a site that works perfectly in a browser and has no idea anything is wrong.

AgentShoppable runs the exact sequence a shopping agent runs against your live storefront — find the store, read the catalog, search it, pick a variant, create a cart, reach checkout — and tells you where it broke.

Most of that works from the outside, with no plugin at all. This plugin exists for the handful of things a public storefront does not expose:

  • Which page is which policy. Agents will not recommend a purchase when they cannot state your return and shipping terms. Your storefront lists pages; it does not say which one WooCommerce treats as the refund policy. This plugin does.
  • Fields the Store API hides. GTIN/barcode, image alt text, stock quantities and weight. Agents use these to match your product against the same product elsewhere.
  • Why a scan looked the way it did. WordPress, WooCommerce and PHP versions, your theme, active plugins, and whether coming-soon mode or a private-site setting is hiding the store. This turns “your catalog did not answer” into “your catalog did not answer because the store is in coming-soon mode”.
  • Applying fixes you approve. When you approve a fix in AgentShoppable — a missing product description, a blank barcode, empty alt text — this plugin makes that one change and records the previous value so you can undo it.

This plugin never sends anything on its own

It has no scheduled tasks, no background requests and no telemetry. It only answers requests that arrive carrying a valid signature made with a key you generated. Installing it and generating a key sends nothing anywhere. Data leaves your site only when you paste that key into AgentShoppable and start a scan.

How the connection is secured

Every request must carry a timestamp and an HMAC-SHA256 signature over the timestamp, the route and the raw request body, computed with the connection key. Signatures are compared in constant time and requests more than five minutes old are rejected, so a captured request cannot be replayed.

The plugin deliberately does not accept WordPress logins, cookies or Application Passwords for these routes. A stolen admin session cannot read your private product fields or change anything through this plugin. Only the connection key can, and you can rotate or delete it at any time from WooCommerce AgentShoppable.

Fixes are limited to a fixed list of fields in the plugin’s own code — product description, short description, SKU, barcode, weight, and image alt text. A request cannot name an arbitrary meta key, run code, or touch orders, customers, users, settings or prices.

Endpoints added

All under /wp-json/agentshoppable/v1:

  • GET /ping — unsigned. Says only that the plugin is installed and whether a key is set.
  • GET /info — signed. Versions, theme, active plugins, currency, country, store-visibility flags.
  • GET /policies — signed. The pages WooCommerce and WordPress designate as refund, terms, privacy and shipping.
  • GET /product/{id}/private — signed. Barcode, alt text, stock and weight for one product.
  • POST /fix — signed. Applies one approved change and returns the previous value.

External services

This plugin is the store’s half of a connection to AgentShoppable, a service operated by Sela Ventures LLC.

What the plugin sends on its own: nothing. It makes no outbound requests. It has no cron jobs and no telemetry, and it does not phone home to check licences or report usage.

What AgentShoppable reads from your site, and when. Only after you generate a connection key here and paste it into your AgentShoppable account, and only while a scan or an approved fix is running, AgentShoppable calls the signed endpoints listed above. Across those calls it can read: your WordPress, WooCommerce and PHP versions; your active theme and the list of active plugin files; your store currency and base country; whether your store is set to coming-soon or private; the title, URL and text of your published refund, terms, privacy and shipping pages; and, for products it is checking, the barcode, SKU, stock quantity, weight, image URLs and image alt text.

It does not read orders, customers, users, payment settings or any personal data, and this plugin exposes no route that could return them.

When you approve a fix, AgentShoppable sends the new value for one whitelisted product field, and this plugin writes it and stores the previous value on your site so the change can be undone.

Service terms: https://agentshoppable.com/terms
Privacy policy: https://agentshoppable.com/privacy

Using the service requires an AgentShoppable account. The plugin is free and GPL-licensed; the service has a free tier and a paid tier.

Screenshots

Installation

  1. Install and activate the plugin. WooCommerce must be active.
  2. Go to WooCommerce AgentShoppable and click Generate connection key.
  3. Copy the key. It is shown once.
  4. Paste it into your store’s settings at agentshoppable.com and run a scan.

To disconnect, click Disconnect and delete the key. The signed endpoints stop answering immediately. Deleting the plugin removes its stored key and audit log.

FAQ

Do I need this plugin to use AgentShoppable?

No. AgentShoppable scans WooCommerce stores over the public Store API without any plugin. The plugin adds the private fields, the policy-page mapping and the ability to apply fixes. Without it, scans still run and simply report less.

What happens if I lose the connection key?

Generate a new one. Rotating the key immediately invalidates the old one, and you paste the new key into AgentShoppable. The key is stored hashed nowhere and shown once by design, so there is no way to retrieve it later.

Can this plugin change my prices, orders or customers?

No. The fixable fields are a fixed list in the plugin’s source: product description, short description, SKU, barcode, weight and image alt text. Nothing else is reachable, including prices.

Does it work without WooCommerce?

No. WooCommerce is a required plugin. Most of what it reports is WooCommerce-specific.

Does it slow my store down?

No. It registers five REST routes and one admin page. Nothing runs on the front end, and nothing runs on a schedule.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“AgentShoppable” is open source software. The following people have contributed to this plugin.

Contributors

Translate “AgentShoppable” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.0

  • First public release.
  • Signed REST endpoints: /ping, /info, /policies, /product/{id}/private, /fix.
  • Connection key generation, rotation and deletion under WooCommerce AgentShoppable.
  • On-site audit log of every change applied through the plugin, with previous values for undo.
  • Declares compatibility with WooCommerce High-Performance Order Storage.