{"id":344405,"date":"2026-07-23T21:40:49","date_gmt":"2026-07-23T21:40:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ai2web\/"},"modified":"2026-07-23T22:54:07","modified_gmt":"2026-07-23T22:54:07","slug":"ai2web","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ai2web\/","author":18599269,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.4.3","stable_tag":"0.4.3","tested":"7.0.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"AI2Web - MCP, ACP, AP2 & NLWeb for AI Agents","header_author":"AI2Web Foundation","header_description":"Make your website AI-native. Exposes an AI2Web (ai2w) capability manifest, REST and MCP endpoints so AI agents can discover, understand and act on your site. Auto-integrates WooCommerce (product search, order tracking, return\/refund requests) and popular form plugins.","assets_banners_color":"0c150e","last_updated":"2026-07-23 22:54:07","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/ai2web.dev","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":57,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.4.2":{"tag":"0.4.2","author":"rolandfarkas","date":"2026-07-23 22:22:31"},"0.4.3":{"tag":"0.4.3","author":"rolandfarkas","date":"2026-07-23 22:54:07"}},"upgrade_notice":{"0.4.3":"<p>Adds OAuth Protected Resource metadata (RFC 9728), a discovery Link header, Markdown responses for agents, and projects your declared usage policy into robots.txt and a Content-Signal header. Additive and filterable; your robots.txt rules are never changed.<\/p>","0.4.2":"<p>Compatibility and housekeeping release: the plugin now runs cleanly on its declared minimums (PHP 8.0, WordPress 6.0), and the optional Abilities \/ AI Client integrations are explicitly guarded. No configuration changes.<\/p>","0.4.1":"<p>Adds an NLWeb-compatible <code>\/ai2w\/nlweb\/ask<\/code> endpoint so agents that speak NLWeb (nlweb.ai) can query your content and catalogue. Backward compatible; toggle under Settings -&gt; AI2Web.<\/p>","0.4.0":"<p>Adds ACP (Agentic Commerce Protocol) checkout with a Stripe Shared Payment Token handler, an opt-in AP2 (Agent Payments Protocol) merchant surface, richer product data, and local privacy-preserving analytics (a new events table, created on activation). Backward compatible.<\/p>","0.3.0":"<p>Adds agent checkout, llms.txt and agent.json surfaces, and WordPress 7.0 Abilities integration. Backward compatible; review Settings -&gt; AI2Web to toggle the new agent checkout.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3620541,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3620541,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3620541,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3620541,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.4.2","0.4.3"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3620541,"resolution":"1","location":"assets","locale":"","width":3205,"height":1846},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3620541,"resolution":"2","location":"assets","locale":"","width":2961,"height":1548},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3620541,"resolution":"3","location":"assets","locale":"","width":3220,"height":1627}},"screenshots":{"1":"The AI2Web settings page: a live AI Readiness Score and compliance tier, with links to your discovery manifest and MCP endpoint.","2":"Feature toggles: MCP, the agent service, OAuth2 (PKCE), WooCommerce actions, agent checkout, and the ACP and AP2 agentic-commerce surfaces.","3":"The Agent Sales dashboard: agent-driven revenue, orders by protocol (agent checkout, ACP, AP2) and engagement, computed entirely from local data."}},"plugin_section":[],"plugin_tags":[15643,2353,216196,242115,286],"plugin_category":[45],"plugin_contributors":[228208],"plugin_business_model":[],"class_list":["post-344405","plugin","type-plugin","status-publish","hentry","plugin_tags-agents","plugin_tags-ai","plugin_tags-chatgpt","plugin_tags-mcp","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-rolandfarkas","plugin_committers-rolandfarkas"],"banners":{"banner":"https:\/\/ps.w.org\/ai2web\/assets\/banner-772x250.png?rev=3620541","banner_2x":"https:\/\/ps.w.org\/ai2web\/assets\/banner-1544x500.png?rev=3620541","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/ai2web\/assets\/icon-128x128.png?rev=3620541","icon_2x":"https:\/\/ps.w.org\/ai2web\/assets\/icon-256x256.png?rev=3620541","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/ai2web\/assets\/screenshot-1.png?rev=3620541","caption":"The AI2Web settings page: a live AI Readiness Score and compliance tier, with links to your discovery manifest and MCP endpoint."},{"src":"https:\/\/ps.w.org\/ai2web\/assets\/screenshot-2.png?rev=3620541","caption":"Feature toggles: MCP, the agent service, OAuth2 (PKCE), WooCommerce actions, agent checkout, and the ACP and AP2 agentic-commerce surfaces."},{"src":"https:\/\/ps.w.org\/ai2web\/assets\/screenshot-3.png?rev=3620541","caption":"The Agent Sales dashboard: agent-driven revenue, orders by protocol (agent checkout, ACP, AP2) and engagement, computed entirely from local data."}],"raw_content":"<!--section=description-->\n<p><strong>Describe your website once. AI2Web makes it understandable to every AI.<\/strong><\/p>\n\n<p>AI agents are starting to use the web, but the web was built for human eyes. Agents scrape HTML, guess at forms, and render whole pages just to find one price or one button. AI2Web fixes that by publishing a single, structured description of what your site can do, and serving backend-first endpoints agents can call directly. No scraping, no per-vendor rebuild.<\/p>\n\n<p>AI2Web is a vendor-neutral capability layer. It sits <em>above<\/em> protocols like MCP and ACP and speaks whichever one an assistant understands, rather than competing with them.<\/p>\n\n<h4>What it serves<\/h4>\n\n<p>On activation the plugin serves, from your own domain:<\/p>\n\n<ul>\n<li><code>\/.well-known\/ai2w<\/code> - the discovery anchor agents look for<\/li>\n<li><code>\/ai2w<\/code> - your site's AI2Web manifest: identity, capabilities, transports, declared actions, events, governance<\/li>\n<li><code>\/ai2w\/mcp<\/code> - a Model Context Protocol endpoint. Add it to Claude, ChatGPT, Grok or any MCP client and your declared actions become tools the assistant can call<\/li>\n<li><code>\/ai2w\/content<\/code>, <code>\/ai2w\/search<\/code>, <code>\/ai2w\/products<\/code>, <code>\/ai2w\/events<\/code> - live, structured content and catalog<\/li>\n<li><code>\/ai2w\/actions\/*<\/code> - the secure action endpoints<\/li>\n<li><code>\/ai2w\/negotiate<\/code> - capability negotiation (agree a capability set and transport)<\/li>\n<li><code>\/llms.txt<\/code> - a plain-text summary and links, projected from the same manifest<\/li>\n<li><code>\/.well-known\/agent.json<\/code> - a generic agent-capability document, also projected from the manifest<\/li>\n<\/ul>\n\n<p>The last two mean agents that speak <code>llms.txt<\/code> or a generic <code>agent.json<\/code> can use your site without understanding AI2Web first, while <code>\/ai2w<\/code> stays the authoritative source.<\/p>\n\n<h4>Agentic checkout (ACP)<\/h4>\n\n<p>With WooCommerce active, AI2Web can expose an <strong>Agentic Commerce Protocol (ACP) checkout<\/strong> so a shopper's AI agent (for example ChatGPT Instant Checkout) can buy from your store. The agent drives a real WooCommerce cart through a checkout session at <code>\/ai2w\/acp\/checkout_sessions<\/code> - adding items and a chosen variation, setting a shipping address, picking a delivery option, applying a coupon - and sees your live WooCommerce pricing, shipping rates and tax as it goes. A product feed at <code>\/ai2w\/acp\/feed<\/code> lets agents ingest your catalogue. The same flow is available as MCP tools, so any MCP client can run it.<\/p>\n\n<p>Payment stays safe by design. Completing a session hands the store a delegated payment token. AI2Web ships a <strong>Stripe Shared Payment Token<\/strong> handler: when a Stripe secret key is available (set an <code>AI2WEB_STRIPE_SECRET_KEY<\/code> constant in wp-config.php, or configure the WooCommerce Stripe gateway), it confirms a Stripe PaymentIntent for the order total and the buyer is charged in-agent. With no key configured, completion creates a pending order and returns that order's own secure payment link for the customer to pay in the browser. Either way the agent never handles card details, and the whole payment step is filterable (<code>ai2web_acp_complete_payment<\/code>) if you use a different processor. Turn ACP on under Settings -&gt; AI2Web (it requires Agent checkout).<\/p>\n\n<h4>AP2 (Agent Payments Protocol)<\/h4>\n\n<p>AI2Web can also expose a Google <strong>AP2<\/strong> merchant surface (opt-in). AP2 represents a purchase as signed \"mandates\": the store answers a buyer agent's Intent Mandate with a merchant-signed <strong>Cart Mandate<\/strong> that guarantees the items and price for a short window, then settles a user-signed Payment Mandate into a WooCommerce order. It is served at <code>\/ai2w\/ap2<\/code> as a REST binding and a minimal A2A JSON-RPC endpoint, with an agent card and a JWKS that publishes the cart-signing public key so any party can verify the merchant's signature. Enable it under Settings -&gt; AI2Web (it generates an RSA signing key on first use).<\/p>\n\n<h4>WooCommerce<\/h4>\n\n<p>When WooCommerce is active, AI2Web exposes safe commerce actions:<\/p>\n\n<ul>\n<li><strong>search_products<\/strong> - search the catalogue by keyword<\/li>\n<li><strong>check_stock<\/strong> - availability, price and stock by SKU or id<\/li>\n<li><strong>track_order<\/strong> - order status, verified by the billing email on the order<\/li>\n<li><strong>check_return_status<\/strong> - whether a return or refund request already exists<\/li>\n<li><strong>start_return<\/strong> \/ <strong>request_refund<\/strong> - request only. They log the request as an order note for you to action in WooCommerce and never issue a refund or move money automatically. Approval-gated.<\/li>\n<li><strong>start_checkout<\/strong> - an agent assembles a cart and the plugin creates a <em>pending<\/em> order, returning WooCommerce's own secure payment link for the customer to pay in the browser. The agent never handles payment details, and no money moves until the customer pays.<\/li>\n<\/ul>\n\n<h4>Contact forms<\/h4>\n\n<p>If Contact Form 7, Gravity Forms, WPForms, Fluent Forms or Elementor Forms is active, AI2Web exposes a single approval-gated <strong>submit_contact<\/strong> action. On confirmation the enquiry is emailed to your support address (never an arbitrary recipient, so it is not an open relay) and is rate limited per IP.<\/p>\n\n<h4>WordPress 7.0 AI: Abilities API<\/h4>\n\n<p>On WordPress 6.9+\/7.0, AI2Web also registers its actions as native <strong>WordPress Abilities<\/strong>, with AI annotations (read vs. write, destructive). This exposes the same ownership-verified, approval-gated actions to WordPress's own AI Client and MCP Adapter, so a connected assistant can use them through WordPress too. Two surfaces, one definition:<\/p>\n\n<ul>\n<li><code>\/ai2w<\/code> - the public, anonymous, open-protocol surface (ownership and approval gated).<\/li>\n<li>WordPress Abilities - the authenticated WordPress-native surface, gated by WordPress's own auth.<\/li>\n<\/ul>\n\n<h4>Agent service<\/h4>\n\n<p>If you connect an AI provider in WordPress 7.0's Connectors hub, AI2Web exposes <code>\/ai2w\/agent<\/code>, a natural-language endpoint answered by WordPress's built-in AI Client using your provider. The plugin never handles an AI key.<\/p>\n\n<h4>OAuth2 (PKCE)<\/h4>\n\n<p>Agents can authenticate via an OAuth2 authorization-code + PKCE flow, where a logged-in user approves access on a consent screen. Codes are single-use and short-lived, tokens are stored hashed, PKCE uses S256, and the flow is served over HTTPS. Anonymous, ownership-gated access remains the fallback, so a token is never required. OAuth is a security-sensitive feature; review it for your threat model before relying on it, and it can be turned off on the settings page.<\/p>\n\n<h4>AI Readiness Score<\/h4>\n\n<p>A settings page (Settings -&gt; AI2Web) shows a live <strong>AI Readiness Score out of 100<\/strong> and a compliance tier, lets you toggle each feature (MCP, agent service, OAuth2, WooCommerce actions, returns\/refunds, agent checkout, ACP, AP2), and set a public support email.<\/p>\n\n<h4>Agent Sales dashboard<\/h4>\n\n<p>A separate <strong>Agent Sales<\/strong> screen (Settings -&gt; AI2Web Agent Sales) tracks what AI agents actually do on your store, computed entirely from local data - no external service and nothing to set up. It attributes every order an agent created (through agent checkout, ACP or AP2) and shows agent-driven revenue, order count, average order value and pending value for a period you choose, broken down by protocol, with a recent-orders table. It also surfaces engagement from the AI2Web events table: discovery hits, queries, action calls, and query \"misses\" - searches an agent ran that returned nothing, i.e. demand you are not yet meeting, which a read-only crawl of your site could never reveal.<\/p>\n\n<h4>Safe by design<\/h4>\n\n<p>The most important part is what an agent <em>cannot<\/em> do without asking. See the security section below.<\/p>\n\n<p>AI2Web is backend-first and API-driven. It does not scrape your frontend or rely on browser tools.<\/p>\n\n<h3>How it works<\/h3>\n\n<ol>\n<li><strong>Discovery.<\/strong> An agent fetches <code>\/.well-known\/ai2w<\/code>, which points to <code>\/ai2w<\/code>. Reading the manifest never changes anything.<\/li>\n<li><strong>Understanding.<\/strong> The manifest declares your identity, capabilities, transports, and each action's input schema, risk level and whether it needs approval.<\/li>\n<li><strong>Negotiation.<\/strong> The agent can <code>POST \/ai2w\/negotiate<\/code> to agree a capability set and a transport (REST or MCP).<\/li>\n<li><strong>Acting.<\/strong> The agent calls an action over REST (<code>\/ai2w\/actions\/{name}<\/code>) or as an MCP tool. Requests are validated against the declared schema. Sensitive actions return a preview and require explicit confirmation.<\/li>\n<\/ol>\n\n<p>Everything is generated from your live site and detected integrations, and the manifest is filterable so themes and plugins can extend it.<\/p>\n\n<h3>Privacy and security<\/h3>\n\n<ul>\n<li>Discovery and the manifest expose only public metadata. Your admin email is never published; a support contact appears only if you set one.<\/li>\n<li><strong>Ownership before private data.<\/strong> Order actions never trust an order number alone. The caller must also provide the billing email, and it must match the order. A wrong email and a nonexistent order return the identical \"not found\" response, so agents cannot enumerate which orders exist.<\/li>\n<li><strong>Approval before money or commitment.<\/strong> Refunds, returns, checkout and contact enquiries return a preview first and only proceed on explicit confirmation.<\/li>\n<li><strong>Request only for money.<\/strong> Refund and return actions add an order note for you to review and never call WooCommerce's refund process. Checkout creates a <em>pending<\/em> order and hands the customer a payment link; the agent never handles payment.<\/li>\n<li><strong>Rate limited.<\/strong> Order lookups, checkout and enquiries are throttled per IP.<\/li>\n<li>The WordPress Abilities surface requires an authenticated WordPress user; it is gated by WordPress's own permissions.<\/li>\n<li><strong>OAuth2 (PKCE)<\/strong> is served over HTTPS, uses S256, issues single-use short-lived codes, stores tokens hashed, and only issues them after a logged-in user approves on a consent screen. A bearer token authenticates a request but does not elevate its WordPress capabilities.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin does not send any data to an external service by default. One optional feature relies on a third party:<\/p>\n\n<p><strong>Stripe<\/strong> (agent-completed payments)<\/p>\n\n<p>When, and only when, you (a) enable ACP checkout, (b) enter your own Stripe secret key in Settings -&gt; AI2Web, and (c) a shopper's agent completes an order using a delegated Stripe payment token, the plugin sends a single request to the Stripe API (<code>https:\/\/api.stripe.com\/v1\/payment_intents<\/code>) to charge that order. If you do not enter a Stripe key, no request is ever made and no data leaves your site.<\/p>\n\n<p>Data sent to Stripe with that request: the order amount and currency, an order description, the delegated payment token supplied by the agent, the order ID and checkout-session ID, and (if present) the customer's billing email as the receipt address. It is sent over HTTPS at the moment the agent completes payment. No data is sent at any other time.<\/p>\n\n<p>Stripe is a service provided by Stripe, Inc. Please review their terms and privacy policy:<\/p>\n\n<ul>\n<li>Terms: https:\/\/stripe.com\/legal\/ssa<\/li>\n<li>Privacy policy: https:\/\/stripe.com\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>ai2web<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the zip from Plugins -&gt; Add New -&gt; Upload.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Make sure Permalinks are not set to \"Plain\" (Settings -&gt; Permalinks).<\/li>\n<li>Visit Settings -&gt; AI2Web to see your AI Readiness Score and toggle features.<\/li>\n<li>Visit <code>https:\/\/your-site.com\/ai2w<\/code> to see your manifest.<\/li>\n<li>To let an assistant use your site, add <code>https:\/\/your-site.com\/ai2w\/mcp<\/code> as a custom MCP connector.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20expose%20private%20customer%20data%3F\"><h3>Does this expose private customer data?<\/h3><\/dt>\n<dd><p>No. The manifest and discovery endpoints expose only public metadata. Order tracking requires the correct billing email for that order, lookups are rate limited, and a wrong email is indistinguishable from a missing order, so nothing can be enumerated.<\/p><\/dd>\n<dt id=\"can%20an%20ai%20issue%20a%20refund%20or%20take%20payment%20on%20my%20store%3F\"><h3>Can an AI issue a refund or take payment on my store?<\/h3><\/dt>\n<dd><p>No. Refund and return actions only log a request as an order note for you to action in WooCommerce. Checkout creates a pending order and returns a secure payment link; the customer pays in the browser and the agent never handles payment details. No money moves without a human.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20this%20to%20claude%2C%20chatgpt%20or%20grok%3F\"><h3>How do I connect this to Claude, ChatGPT or Grok?<\/h3><\/dt>\n<dd><p>Enable the MCP endpoint on the settings page (on by default), then add <code>https:\/\/your-site.com\/ai2w\/mcp<\/code> as a custom connector \/ MCP server in the assistant. Your declared actions appear as tools.<\/p><\/dd>\n<dt id=\"can%20a%20shopper%20check%20out%20through%20an%20ai%20agent%20%28acp%20%2F%20chatgpt%20instant%20checkout%29%3F\"><h3>Can a shopper check out through an AI agent (ACP \/ ChatGPT Instant Checkout)?<\/h3><\/dt>\n<dd><p>Yes, if you enable ACP checkout (Settings -&gt; AI2Web; it needs Agent checkout on). AI2Web implements the Agentic Commerce Protocol 2026-04-17 checkout sessions and a product feed, backed by a real WooCommerce cart, so a shopper's agent can assemble a cart, choose a variation, add a shipping address and coupon, and see live shipping and tax. To charge in-agent, provide a Stripe secret key (an <code>AI2WEB_STRIPE_SECRET_KEY<\/code> constant in wp-config.php, or the WooCommerce Stripe gateway): AI2Web then confirms a Stripe PaymentIntent from the Shared Payment Token the agent supplies. Without a key, completing a checkout creates a pending order and returns its secure payment link for the customer to pay in the browser. Either way the agent never handles card details.<\/p><\/dd>\n<dt id=\"what%20is%20the%20difference%20between%20acp%20and%20ap2%3F\"><h3>What is the difference between ACP and AP2?<\/h3><\/dt>\n<dd><p>Both let AI agents buy from your store; they are complementary and you can enable either or both. ACP (OpenAI\/Stripe) is a session-based checkout that powers ChatGPT Instant Checkout - the agent drives a live cart and completes with a Shared Payment Token. AP2 (Google) is mandate-based: your store signs a Cart Mandate guaranteeing the price, and the buyer's agent settles it with a signed Payment Mandate. AI2Web implements the merchant side of both from the same WooCommerce catalogue.<\/p><\/dd>\n<dt id=\"what%20is%20%2Fllms.txt%20and%20%2F.well-known%2Fagent.json%3F\"><h3>What is \/llms.txt and \/.well-known\/agent.json?<\/h3><\/dt>\n<dd><p>They are alternative projections of the same manifest, for agents that read those formats. You do not maintain them separately; they are generated from <code>\/ai2w<\/code>.<\/p><\/dd>\n<dt id=\"what%20are%20the%20wordpress%20abilities%20it%20registers%3F\"><h3>What are the WordPress Abilities it registers?<\/h3><\/dt>\n<dd><p>On WordPress 6.9+\/7.0, the plugin registers its actions with the native Abilities API so WordPress's own AI Client and MCP Adapter can use them. This surface is authenticated (gated by WordPress permissions), separate from the public <code>\/ai2w<\/code> surface.<\/p><\/dd>\n<dt id=\"does%20it%20clash%20with%20woocommerce%2010.9%27s%20own%20agent%20abilities%3F\"><h3>Does it clash with WooCommerce 10.9's own agent abilities?<\/h3><\/dt>\n<dd><p>No. WooCommerce 10.9+ ships its own canonical abilities (product and order query, create, update, etc.) into the same Abilities API. Those are merchant-facing and authenticated, for a store operator driving their shop from an AI client. AI2Web's actions are the opposite: customer-facing, anonymous, and ownership-gated (an external shopper's agent with no WordPress account), served from <code>\/ai2w\/mcp<\/code> and REST. To keep the native, authenticated surface tidy, AI2Web stops registering its read actions that WooCommerce now covers canonically (<code>search_products<\/code>, <code>check_stock<\/code>, <code>track_order<\/code>) as WordPress abilities when WooCommerce 10.9+ is active. They stay available on the public <code>\/ai2w<\/code> surface, which WooCommerce's abilities do not serve.<\/p><\/dd>\n<dt id=\"do%20i%20need%20openai%2Fanthropic%20to%20use%20ai2web%3F\"><h3>Do I need OpenAI\/Anthropic to use AI2Web?<\/h3><\/dt>\n<dd><p>No. The manifest, feeds and endpoints are useful today, and the MCP endpoint works with current assistant connectors without any AI key on your side.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20multisite%3F\"><h3>Does it work with multisite?<\/h3><\/dt>\n<dd><p>Subdomain multisite works: each subsite serves its own manifest. Subdirectory multisite also works for <code>\/ai2w<\/code> and its routes (the request path is resolved against each site's home URL); the domain-root <code>\/.well-known\/<\/code> anchor belongs to the network's main site, so subsites are discovered via <code>\/ai2w<\/code> and the <code>&lt;link rel=\"ai2w\"&gt;<\/code> tag.<\/p><\/dd>\n<dt id=\"%2F.well-known%2Fai2w%20returns%20a%20404%20on%20my%20server\"><h3>\/.well-known\/ai2w returns a 404 on my server<\/h3><\/dt>\n<dd><p>On Apache with the standard WordPress .htaccess, requests reach WordPress and the plugin serves the anchor. On some nginx setups a <code>location ^~ \/.well-known\/<\/code> block serves that path directly and never reaches WordPress; add a rule to pass <code>\/.well-known\/ai2w<\/code> to WordPress, or serve it as a static pointer to <code>\/ai2w<\/code>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20authenticate%20an%20agent%20%28oauth2%29%3F\"><h3>How do I authenticate an agent (OAuth2)?<\/h3><\/dt>\n<dd><p>Enable OAuth2 (PKCE) on the settings page. An agent sends the user to <code>\/ai2w\/oauth\/authorize<\/code>, the user approves on a consent screen, and the agent exchanges the code for a token at <code>\/ai2w\/oauth\/token<\/code> (PKCE S256). The token is then sent as an <code>Authorization: Bearer<\/code> header. Anonymous, ownership-gated access still works without a token.<\/p><\/dd>\n<dt id=\"how%20do%20i%20customise%20the%20manifest%3F\"><h3>How do I customise the manifest?<\/h3><\/dt>\n<dd><p>Use the <code>ai2web_manifest<\/code> filter, or the targeted <code>ai2web_support_contact<\/code>, <code>ai2web_governance<\/code>, <code>ai2web_usage_policy<\/code>, <code>ai2web_legal<\/code>, <code>ai2web_knowledge<\/code>, <code>ai2web_oauth_allowed_clients<\/code> and <code>ai2web_oauth_allow_insecure<\/code> filters.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.3<\/h4>\n\n<ul>\n<li><strong>OAuth Protected Resource (RFC 9728)<\/strong>: new <code>\/.well-known\/oauth-protected-resource<\/code> document telling agents (and MCP clients) which authorization server guards the AI2Web endpoints. Served only when OAuth2 is enabled.<\/li>\n<li><strong>Content Signals + robots.txt projection<\/strong>: the <code>usage_policy<\/code> you already declare in the manifest is now projected into robots.txt as a <code>Content-Signal<\/code> directive and sent as a <code>Content-Signal<\/code> response header, so crawlers can actually read your stated preferences. Additive only - your existing robots.txt rules are never modified - and filterable via <code>ai2web_project_robots_txt<\/code>.<\/li>\n<li><strong>Discovery <code>Link<\/code> header<\/strong>: every front-end response advertises the manifest via <code>Link: &lt;...\/ai2w&gt;; rel=\"ai2w\"<\/code> (RFC 8288), so non-HTML clients discover it without parsing a page. Filterable via <code>ai2web_send_discovery_headers<\/code>.<\/li>\n<li><strong>Markdown for agents<\/strong>: <code>\/ai2w\/content<\/code> returns Markdown when the request sends <code>Accept: text\/markdown<\/code> (with <code>Vary: accept<\/code>); JSON remains the default.<\/li>\n<\/ul>\n\n<h4>0.4.2<\/h4>\n\n<ul>\n<li><strong>Compatibility<\/strong>: the plugin no longer relies on <code>array_is_list()<\/code>, so it runs on its declared minimums (PHP 8.0, WordPress 6.0) rather than needing PHP 8.1 \/ WordPress 6.5.<\/li>\n<li>The optional <strong>WordPress 6.9 Abilities API<\/strong> and <strong>WordPress 7.0 AI Client<\/strong> integrations are now explicitly guarded, so they are never called on cores that do not provide them.<\/li>\n<li>Housekeeping: added a <code>License URI<\/code> header, escaped an admin readiness glyph, trimmed an over-long upgrade notice, and documented the OAuth redirect and table-name query annotations.<\/li>\n<li>No configuration changes; nothing to do after updating.<\/li>\n<\/ul>\n\n<h4>0.4.1<\/h4>\n\n<ul>\n<li>New <strong>NLWeb (nlweb.ai) endpoint<\/strong>: exposes <code>\/ai2w\/nlweb\/ask<\/code>, an NLWeb-compatible natural-language query over your posts, pages and WooCommerce products, returning schema.org-style results. Agents that speak NLWeb can now search your site through AI2Web, and the surface is advertised in the manifest under <code>transports.nlweb<\/code> (plus a <code>conversational<\/code> capability). It is a keyword projection over WordPress search, not NLWeb's own semantic engine. Toggle under Settings -&gt; AI2Web.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>New <strong>Agent Sales dashboard<\/strong> (Settings -&gt; AI2Web Agent Sales): see what AI agents are doing on your store, computed entirely from local data. Shows agent-driven revenue, order count, average order value and pending value over a selectable window, a breakdown by protocol (agent checkout \/ ACP \/ AP2), a recent agent-orders table, and engagement from the local events table (discovery hits, queries, query \"misses\" that reveal unmet demand, and action calls). Nothing is sent to any external service.<\/li>\n<li>New <strong>ACP (Agentic Commerce Protocol) checkout<\/strong> (spec 2026-04-17): a customer-facing agentic checkout so a shopper's agent (for example ChatGPT Instant Checkout) can run a full cart -&gt; shipping -&gt; coupon -&gt; pay flow against a real WooCommerce cart. Adds checkout sessions at <code>\/ai2w\/acp\/checkout_sessions<\/code> (create, retrieve, update, complete, cancel), a product feed at <code>\/ai2w\/acp\/feed<\/code>, and the five matching MCP tools (create\/get\/update\/complete\/cancel_checkout_session). Live WooCommerce pricing, shipping rates, coupons and tax are projected as ACP totals in minor units. Includes a <strong>Stripe Shared Payment Token handler<\/strong>: when a Stripe secret key is available (an <code>AI2WEB_STRIPE_SECRET_KEY<\/code> constant or the WooCommerce Stripe gateway), completing a checkout charges the buyer in-agent by confirming a Stripe PaymentIntent; with no key it degrades safely to a pending order plus that order's secure pay link, so the agent never handles card data. Toggle under Settings -&gt; AI2Web (requires Agent checkout).<\/li>\n<li>New <strong>AP2 (Agent Payments Protocol, Google) merchant surface<\/strong> (v0.2.0, opt-in): the store answers a buyer agent's Intent Mandate with a merchant-signed <strong>Cart Mandate<\/strong> (a W3C PaymentRequest guaranteeing items and price), and settles a user-signed Payment Mandate into a WooCommerce order. Exposed at <code>\/ai2w\/ap2<\/code> as both a REST binding (<code>\/cart<\/code>, <code>\/payment<\/code>) and an A2A JSON-RPC <code>message\/send<\/code> endpoint that returns proper A2A Task artifacts, with an agent card discoverable at both <code>\/ai2w\/ap2\/agent-card<\/code> and <code>\/.well-known\/agent-card.json<\/code> (advertising the AP2 extension) and a JWKS (<code>\/ai2w\/ap2\/jwks<\/code>) publishing the cart-signing key. Carts support multiple items and quantities. Carts are signed as RS256 JWTs (an RSA key is generated on first use, or supplied via an <code>AI2WEB_AP2_PRIVATE_KEY<\/code> constant). Settlement runs through the <code>ai2web_ap2_settle_payment<\/code> filter, falling back to a pending order + pay link. Enable under Settings -&gt; AI2Web.<\/li>\n<li><strong>Richer product data<\/strong>: product and variation detail for agents. <code>check_stock<\/code> and the catalogue now report product type, attributes (size\/colour\/etc.), and, for variable products, each purchasable variation with its own id, SKU, price, selecting attributes and stock, plus the price range. <code>start_checkout<\/code> accepts a <code>variation_id<\/code> (to buy a specific variant) and an optional <code>coupon<\/code> code.<\/li>\n<li>New <strong>analytics<\/strong> (RFC-0016 parity with the reference server): personal-data-free, server-side interaction events stored in a local plugin table and fired as an <code>ai2web_event<\/code> action so operators can forward them anywhere. Records discovery, query, and action events, including query \"misses\" (the demand signal a read-only crawl cannot produce). Filters are sanitised to non-identifying scalars, the agent identity is coarse (User-Agent only, never an end-user), rows auto-prune after 90 days, and the whole thing is filterable off via <code>ai2web_analytics_enabled<\/code>.<\/li>\n<li><strong>WooCommerce 10.9+ interop<\/strong>: WooCommerce 10.9 ships its own canonical product\/order abilities into WordPress's Abilities API and MCP Adapter. To avoid listing near-duplicates next to them on that authenticated, merchant-facing surface, AI2Web no longer registers its <code>search_products<\/code>, <code>check_stock<\/code>, or <code>track_order<\/code> reads as WordPress abilities when WooCommerce 10.9+ is active (WooCommerce's <code>products-query<\/code> \/ <code>orders-query<\/code> cover them). Every AI2Web action, including those three, remains fully available on the anonymous, ownership-gated <code>\/ai2w\/mcp<\/code> and REST surfaces, which WooCommerce's abilities do not provide. Filterable via <code>ai2web_abilities_superseded_by_woocommerce<\/code>.<\/li>\n<li><strong>Hardened OAuth2 server<\/strong>: least-privilege bearer authentication, so a token authenticates a request without elevating its WordPress capabilities.<\/li>\n<li><strong>Strict PKCE and scope validation<\/strong> on the authorize endpoint: the <code>code_challenge<\/code> and requested scopes are validated up front and rejected if malformed.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Manifest upgraded to AI2Web protocol v0.2 (additive, backward compatible): governance (rate limits and consent mode), a protective usage policy, opt-in legal fields, and knowledge sources. All filterable.<\/li>\n<li>New <strong>agent service<\/strong> at <code>\/ai2w\/agent<\/code>, answered by WordPress 7.0's built-in AI Client using your connected provider (no AI key handled by the plugin).<\/li>\n<li>New <strong>OAuth2 (PKCE)<\/strong> authenticated access: authorization-code + PKCE (S256) flow with a consent screen, single-use codes, hashed tokens and HTTPS enforcement. Anonymous, ownership-gated access remains the fallback.<\/li>\n<li>New <strong>agent checkout<\/strong>: agents can assemble a cart into a pending order and receive a secure payment link. The customer pays in the browser; the agent never handles payment.<\/li>\n<li>New multi-surface projections: serves <code>\/llms.txt<\/code> and <code>\/.well-known\/agent.json<\/code> from the same manifest.<\/li>\n<li>WordPress 7.0 <strong>Abilities API<\/strong> integration: registers the actions as native WordPress abilities (with AI annotations) so the built-in AI Client and MCP Adapter can use them.<\/li>\n<li>Added a <code>&lt;link rel=\"ai2w\"&gt;<\/code> discovery tag and a subdirectory \/ subdirectory-multisite path fix.<\/li>\n<li>Admin now surfaces detected contact-form plugins.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>WooCommerce actions: product search, stock check, order tracking (billing-email verified), and return\/refund requests (logged for the merchant, never auto-processed).<\/li>\n<li>MCP endpoint at <code>\/ai2w\/mcp<\/code> exposing declared actions as tools for Claude \/ ChatGPT connectors.<\/li>\n<li>Admin settings page with a live AI Readiness Score, feature toggles and a support-email field.<\/li>\n<li>Contact action delivers approved enquiries to your support address (rate limited).<\/li>\n<li>Per-IP rate limiting on order lookups and enquiries.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial draft: manifest, discovery, content\/search\/products\/events, WooCommerce + form detection, negotiation.<\/li>\n<\/ul>","raw_excerpt":"Make your website AI-native. One open manifest plus REST and MCP endpoints so AI agents can discover, understand and safely act on your site.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/344405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=344405"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rolandfarkas"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=344405"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=344405"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=344405"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=344405"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=344405"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=344405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}