Description
Building an SPA or mobile app on WooCommerce? Stop receiving 50+ fields when your screen needs 3 — and stop stitching together a JWT plugin, a filtering snippet, and a Stripe integration to get there.
ShopMobi is an all-in-one WooCommerce REST API layer for developers building single-page apps, Flutter apps, React Native apps, or any headless WooCommerce frontend. It ships two things:
- Field Filtering — trim the responses of the existing WooCommerce
wc/v3endpoints (products, variations, orders, customers). No new routes: you keep calling the standard WooCommerce REST API and opt into smaller responses. - Custom Endpoints — ready-made routes under
shopmobi/v1for login, registration, password reset, store settings, and Stripe payments.
📖 Full API reference with every request, response and error code: GitHub documentation
At a Glance
Same endpoint, same credentials, one query parameter added:
GET /wp-json/wc/v3/products/101?fields=id,name,price
- Fields returned per product: 66 by default only the ones you ask for
- Payload for one product: ~2.8 KB ~130 B
- Payload for a 20-product listing screen: ~56 KB ~2.5 KB
- New endpoints to learn: none — it’s the same
wc/v3route
Why ShopMobi?
- One plugin instead of three. A headless WooCommerce frontend usually needs a JWT/auth plugin, hand-written response-filtering code, and a separate Stripe integration. ShopMobi ships all of it as one tested package.
- Built for SPA and mobile clients. Flutter, React Native, and native apps pay for every extra byte in load time, memory, and mobile data. A product screen that needs 4 fields shouldn’t download 60+.
- GraphQL-like control without leaving REST. Pick exactly the fields you want, per request — no schema, no query language, no extra server.
- Auth, password reset, and Stripe included. Login, registration, profile updates, password reset, and Stripe
PaymentIntent/EphemeralKeycreation are ready to use, so you don’t build and secure them yourself.
Field Filtering
Add an include list or an exclude list to any supported wc/v3 request, as a header or a query parameter:
- Include only these fields: header
X-WC-Fields: id,name,priceor query?fields=id,name,price - Exclude these fields: header
X-WC-Except: meta_dataor query?except_fields=meta_data
How it behaves:
- WooCommerce builds its normal response first — every hook, permission check, and sanitization rule still runs. ShopMobi only trims the top-level keys right before the response is sent.
- Collections (e.g. a product list) are trimmed item by item, so every item comes back in the same shape.
- If a header and a query parameter are both sent, the header wins. If an include and an exclude list are both sent, both apply.
- With an include list, only the listed fields come back — add
idyourself if your app needs it.
Example — only the fields a product list screen needs:
curl "https://example.com/wp-json/wc/v3/products?fields=id,name,price,images" \
-u consumer_key:consumer_secret
Response (every product in the list is trimmed the same way):
[
{
"id": 101,
"name": "Classic T-Shirt",
"price": "24.00",
"images": [{ "id": 55, "src": "https://example.com/wp-content/uploads/tshirt.jpg" }]
}
]
Example — drop heavy fields from orders instead:
curl "https://example.com/wp-json/wc/v3/orders?except_fields=meta_data,_links,tax_lines" \
-u consumer_key:consumer_secret
Supported endpoints: products, product variations, orders, order refunds, and customers (list and single-item routes).
Variation enhancement: product responses return full variation objects instead of raw variation IDs — pricing, sale status, SKU, stock, attributes, and image URL — so a product page doesn’t need one extra request per variation.
Custom Endpoints
All routes live under https://your-site.com/wp-json/shopmobi/v1:
POST /users/login— log in with username and password (cookie-based, rate limited)POST /users/register— create a customer account (rate limited)POST /users/update-profile— update name and phone (requires login)POST /users/reset-password/generate— email a password reset keyPOST /users/reset-password/verify— verify the key and set a new passwordGET /general-settings— store country, currency format, and active payment gatewaysGET /store-location— store address (requires login)GET /payment-gateways— active payment gatewaysPOST /stripe-payment— create a StripePaymentIntent+EphemeralKeyfor Stripe’s mobilePaymentSheet(requires login)
Endpoints marked requires login need a valid WordPress session: cookie authentication with an X-WP-Nonce header, or Application Passwords over HTTP Basic Auth. /users/login sets standard WordPress auth cookies; it does not return a bearer token.
Request bodies, response examples, and error codes for every endpoint are in the GitHub documentation.
Third-Party Services
This plugin optionally integrates with Stripe (https://stripe.com) for payment processing. The Stripe integration is inactive until you provide API keys under WooCommerce > API Optimizer.
When the /shopmobi/v1/stripe-payment endpoint is called, payment data (amount, currency, Stripe customer ID) is sent directly to Stripe’s servers. No payment data passes through ShopMobi or any other third party.
- Stripe Privacy Policy: https://stripe.com/privacy
- Stripe Terms of Service: https://stripe.com/legal
Your Stripe API keys are stored in your WordPress database and are never shared with the plugin author.
Privacy
This plugin stores data in your own WordPress database only:
- Stripe customer IDs (
stripe_cust_iduser meta) — created when a user makes a Stripe payment, and shared only with Stripe to identify returning customers. - Password reset keys — handled entirely by WordPress core (
get_password_reset_key()/reset_password()).
The plugin does not track users, send analytics, or transmit personal data to ShopMobi or any third party, except payment data sent directly to Stripe when the Stripe endpoint is used.
Screenshots


id, name, and price.
Installation
Standard Installation (Recommended)
- Go to Plugins > Add New > Upload Plugin in your WordPress admin.
- Upload the plugin zip file and click Install Now.
- Click Activate Plugin.
- Optionally, go to WooCommerce > API Optimizer to enter your Stripe API keys.
Installation from Source
- Clone the repository and navigate to the plugin folder.
- Run:
composer install --no-dev --optimize-autoloader - Copy the folder to
wp-content/plugins/and activate from the Plugins screen.
Requirements
- WordPress 5.8 or higher
- WooCommerce 6.0 or higher
- PHP 7.4 or higher
FAQ
-
Where is the full API documentation?
-
Every endpoint, with request bodies, response examples, and error codes, is documented on GitHub.
-
Does field filtering affect server performance?
-
The full WooCommerce response is built internally before filtering is applied, so server processing time is unchanged. The benefit is a smaller network payload for mobile and headless clients.
-
Does this replace the WooCommerce REST API?
-
No. This plugin adds a filtering layer on top of the standard WooCommerce REST API, and adds separate custom endpoints under
shopmobi/v1alongside it. All existing WooCommerce authentication, permissions, and hooks still apply. -
What happens if I stop using field filtering — is there anything to migrate?
-
Nothing. Filtering only runs when a request includes
fields/X-WC-Fieldsorexcept_fields/X-WC-Except. Stop sending those and every endpoint returns WooCommerce’s normal, full response. -
Can I use both a header and a query parameter at the same time?
-
The header takes priority. If
X-WC-Fieldsis present, thefieldsquery parameter is ignored for that request — same rule forX-WC-Exceptvsexcept_fields. -
Is Stripe required?
-
No. Stripe is completely optional. All other features — field filtering, auth endpoints, general settings — work without any Stripe configuration.
-
Does this work with WooCommerce HPOS (High-Performance Order Storage)?
-
Yes. The plugin filters WooCommerce REST API responses and does not make direct database queries, so it is fully compatible with HPOS.
-
Is the plugin compatible with caching plugins?
-
The field filtering works on REST API responses. If your caching plugin caches REST API responses, those cached responses will not be filtered. Disable REST API caching or configure it to vary by the
X-WC-Fields/X-WC-Exceptheaders. -
Where are Stripe API keys stored?
-
Stripe API keys are stored in the WordPress options table via the standard WordPress Settings API (
shopmobi_ao_stripe_secret_key,shopmobi_ao_stripe_public_key). They are never logged, exposed in source code, or transmitted to any party other than Stripe. -
Does the plugin collect any data?
-
The plugin stores the following data in your own WordPress database:
- Stripe customer IDs in user meta (
stripe_cust_id) — only when Stripe is used - Temporary password reset keys — handled entirely by WordPress core and invalidated automatically after use
No data is sent to ShopMobi or any external service other than Stripe (when explicitly used).
- Stripe customer IDs in user meta (
-
Can I use this plugin without WooCommerce?
-
No. WooCommerce must be installed and active. If WooCommerce is not detected, the plugin will show an admin notice and will not register any hooks or endpoints.
Reviews
Contributors & Developers
“ShopMobi – API Optimizer for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “ShopMobi – API Optimizer for WooCommerce” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.0
- Initial release.
- Field filtering via
X-WC-Fields/X-WC-Exceptheaders andfields/except_fieldsquery parameters. - Applies to products, orders, customers, and variation endpoints.
- Auth endpoints: login, register, update profile.
- Password reset endpoints: generate and verify.
- General settings endpoint: country, currency, store location, active gateways.
- Payment gateways endpoint.
- Stripe PaymentIntent endpoint with EphemeralKey support.
- Product variation response enhancer.
- Admin settings page under WooCommerce > API Optimizer.
