Webkoding ShopKit Connect for WooCommerce

Description

Webkoding ShopKit Connect for WooCommerce is the companion plugin of the ShopKit mobile app. Products, cart and checkout come from WooCommerce’s own Store API; this plugin adds what a shopping app needs on top of it:

  • App keys and a connection code. Create a key under WooCommerce > ShopKit Connect and scan its QR code in the app (“Connect your store”) or paste the connection JSON there; the app then shows your store, without a rebuild. For a production build the same JSON goes into the app’s build configuration instead. Your WooCommerce REST API keys never go into the app.
  • Customer accounts. Sign in, register, password reset by email, profile and password changes, and account deletion. Sign-in uses short-lived tokens that are stored hashed, can be revoked, and are throttled against password guessing.
  • Checkout on your own checkout page. The app hands its cart to your normal WooCommerce checkout in a secure in-app browser, so every payment gateway you already use works. The hand-off link works once, expires after 5 minutes and only opens from the app that asked for it.
  • Order history with status timeline, customer notes and shipment tracking numbers (from WooCommerce Shipment Tracking or compatible plugins).
  • Address book, wishlist and a notification feed.
  • Push notifications when an order status changes, plus broadcasts, through Firebase Cloud Messaging. Messages are sent in the background with Action Scheduler, so orders never wait for them.
  • Extras the app’s screens use: review summary per star, review writing, sale end dates for countdowns, units sold, colour swatches for attribute terms, and coupons you choose to show in the app.
  • Store settings for the app: logo (splash screen), a primary colour (used as the accent by the Core Kit design; the niche designs keep their own palette), home screen banners, contact and legal links, feature switches.

The plugin works with HPOS (custom order tables), the block checkout and the classic checkout.

Push notifications and Firebase

Push is off the network by default: the “Log only” driver writes each notification to the plugin log. To deliver real notifications, choose Firebase Cloud Messaging on the Push tab and enter the path of a Firebase service account key file. See “External services” below.

External services

This plugin connects to Google services only when you choose “Firebase Cloud Messaging” as the push driver on WooCommerce > ShopKit Connect > Push. With the default “Log only” driver nothing is sent anywhere.

When Firebase is enabled:

  • Google OAuth 2.0 token endpoint (https://oauth2.googleapis.com/token): the plugin sends a JSON Web Token signed with your service account key to obtain a short-lived access token. Sent: your service account’s email address and the requested scope. This happens at most about once per hour.
  • Firebase Cloud Messaging HTTP v1 API (https://fcm.googleapis.com/v1/projects/{your-project}/messages:send): for each notification the plugin sends the device’s registration token, the notification title and text (for example “Order #123: Completed”) and a small data payload: the notification type, and for order updates the order id and its new status. This happens when an order status changes, when you send a broadcast, and when you send a test notification.

Firebase is a Google service: Firebase Terms of Service, Google Privacy Policy. Firebase Cloud Messaging is free of charge at the time of writing; check Google’s current pricing for your project.

The QR code on the settings page is generated inside the plugin; no external service is used for it. The Status tab sends one request to your own site’s Store API to check that it answers; that request does not leave your server.

Screenshots

Installation

  1. Install and activate WooCommerce.
  2. Install this plugin from Plugins > Add New, or upload the zip, and activate it.
  3. Go to WooCommerce > ShopKit Connect. Fix anything the Status tab marks red (HTTPS is required for a live app).
  4. On the App keys tab, create a key. In the ShopKit app open “Connect your store” and scan the QR code or paste the connection JSON. For a production build, pass the JSON at build time instead (--dart-define=SHOPKIT_CONNECTION=...), which also hides the in-app connect screen. The key is shown only once.
  5. Optional: set your logo, colour, banners and links on the App settings tab, and Firebase on the Push tab.

FAQ

Do I need the ShopKit app?

Yes. This plugin is the server side of the ShopKit mobile app. On its own it adds REST endpoints and an admin page, nothing on your storefront.

Does the app see my WooCommerce REST API keys?

No. The app only gets an app key created by this plugin. It identifies the app and can be revoked at any time; customer data needs the customer’s own sign-in on top of it.

Which payment gateways work?

All of them. Payment happens on your normal checkout page inside the app’s in-app browser, then the app shows its order confirmation.

Can shop managers or administrators sign in to the app?

No. Accounts that can edit posts, manage WooCommerce or manage options are store staff, and staff never get an app token, so an app token can never become a back-office login. Accounts protected by two-factor authentication are refused too, because the app cannot complete a second factor. Use a customer account to test the app. Developers can change the staff capability list with the wkskc_staff_capabilities filter and add rules with wkskc_user_can_use_app.

What happens when a customer deletes their account in the app?

The plugin deletes the WordPress user, their WooCommerce customer data, their wishlist, devices and notifications, and anonymises their own orders if “Remove personal data from orders on request” is on in WooCommerce > Settings > Accounts & Privacy. Data that is only linked by email address (for example guest orders or comments) is not erased automatically, because the app cannot prove the customer owns that address. Instead a standard WordPress “Erase Personal Data” request is created: its owner confirms it by email and you process it under Tools > Erase Personal Data.

Is email address verification required for a changed email?

Yes. When a customer changes their email in the app, the new address receives a confirmation link and the change only happens after it is opened.

How do I show a colour dot for attribute terms?

Edit a term under Products > Attributes and fill in “Swatch colour (ShopKit app)”. Colours set by popular variation swatch plugins are read too.

How do I list a coupon in the app?

Tick “Show in the ShopKit app” on the coupon. Coupons that are expired, used up or limited to specific emails are never listed.

My host blocks the Authorization header.

The app can send the token in an X-ShopKit-Token header instead.

Which languages are supported?

The plugin is translation-ready; translations are provided as language packs from translate.wordpress.org. Its REST API answers the app in the language the app asks for (the Accept-Language header) when a translation is available; admin and shop pages keep the site language.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Webkoding ShopKit Connect for WooCommerce” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.1

  • Security: the checkout hand-off no longer stores any WordPress session token; the web session is created when the one-time link is redeemed. Existing hand-off links are cleared on update.
  • Security: a new app key is shown once on the page that creates it and is never stored, not even briefly; refreshing the status checks needs a nonce.
  • Translations now come from translate.wordpress.org.

1.0.0

  • First release.
  • Translations: Turkish and Arabic included.