{"id":358677,"date":"2026-08-26T16:09:49","date_gmt":"2026-08-26T16:09:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/roki-connect-for-woocommerce\/"},"modified":"2026-08-26T16:23:16","modified_gmt":"2026-08-26T16:23:16","slug":"roki-connect-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/roki-connect-for-woocommerce\/","author":23554847,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.7","stable_tag":"1.1.7","tested":"7.1","requires":"6.2","requires_php":"8.0","requires_plugins":null,"header_name":"ROKI Connect for WooCommerce","header_author":"ROKI","header_description":"Cobra con tarjeta en tu tienda WooCommerce a traves de ROKI Connect. Checkout clasico y por bloques, webhooks verificados, anulaciones y reembolsos desde el panel.","assets_banners_color":"0b1a20","last_updated":"2026-08-26 16:23:16","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/connect.roki.la\/conectores\/woocommerce","header_author_uri":"https:\/\/roki.la","rating":0,"author_block_rating":0,"active_installs":0,"downloads":55,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.1.7":{"tag":"1.1.7","author":"rokiconnect","date":"2026-08-26 16:23:16"}},"upgrade_notice":{"1.1.7":"<p>Directory housekeeping plus one hardening fix. Nothing in your configuration changes and no screen\nlooks different.<\/p>","1.1.4":"<p>Important if you have, or will have, another ROKI plugin on the same WordPress: without this version\nthe second one to be installed takes the site down. With a single ROKI install it does not affect\nyou.<\/p>","1.1.3":"<p>Fixes a payment from another store connected to the same ROKI account being able to mark an order of\nthis one as paid. If you only have one store it does not affect you; if you have two, update.<\/p>","1.1.2":"<p>The card fields inside your store are no longer marked as Beta. Nothing in your configuration\nchanges.<\/p>","1.1.1":"<p>Orders taken with the embedded card fields are back in reconciliation and in the query made when the\ncustomer returns from the checkout. Before, they fell out of both and a lost webhook left them\npending forever.<\/p>","1.1.0":"<p>Adds the option to charge with the card fields inside your own store. Your current configuration\nkeeps working exactly the same: the new mode has to be chosen.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3667440,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3667440,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3667440,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3667440,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.7"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3667440,"resolution":"1","location":"assets","locale":"","width":1180,"height":935},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3667440,"resolution":"2","location":"assets","locale":"","width":1280,"height":1500},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3667440,"resolution":"3","location":"assets","locale":"","width":1060,"height":363},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3667440,"resolution":"4","location":"assets","locale":"","width":778,"height":681}},"screenshots":{"1":"ROKI Connect offered as a payment method in the store checkout.","2":"The settings screen, with the selector between the two ways of charging.","3":"The diagnostics, checking the configuration point by point.","4":"A paid order, showing its ROKI transaction identifier."}},"plugin_section":[],"plugin_tags":[3148,11475,277679,6593,1887],"plugin_category":[45],"plugin_contributors":[277680],"plugin_business_model":[],"class_list":["post-358677","plugin","type-plugin","status-publish","hentry","plugin_tags-checkout","plugin_tags-credit-card","plugin_tags-honduras","plugin_tags-payment-gateway","plugin_tags-payments","plugin_category-ecommerce","plugin_contributors-rokiconnect","plugin_committers-rokiconnect"],"banners":{"banner":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/banner-772x250.png?rev=3667440","banner_2x":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/banner-1544x500.png?rev=3667440","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/icon-128x128.png?rev=3667440","icon_2x":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/icon-256x256.png?rev=3667440","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/screenshot-1.png?rev=3667440","caption":"ROKI Connect offered as a payment method in the store checkout."},{"src":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/screenshot-2.png?rev=3667440","caption":"The settings screen, with the selector between the two ways of charging."},{"src":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/screenshot-3.png?rev=3667440","caption":"The diagnostics, checking the configuration point by point."},{"src":"https:\/\/ps.w.org\/roki-connect-for-woocommerce\/assets\/screenshot-4.png?rev=3667440","caption":"A paid order, showing its ROKI transaction identifier."}],"raw_content":"<!--section=description-->\n<p>ROKI Connect lets your WooCommerce store accept credit and debit cards in Honduran lempira (HNL).<\/p>\n\n<p>The plugin interface is in Spanish. The settings labels, the admin notices and the texts your customers read are written for Honduran merchants and are not translated. Only this readme is in English, because the plugin directory requires it.<\/p>\n\n<p><strong>Two ways to charge, and you pick<\/strong><\/p>\n\n<ul>\n<li><strong>Card fields in your store.<\/strong> ROKI draws the card fields inside your own checkout, in a secure iframe. The customer never leaves your page and the card number never touches your server.<\/li>\n<li><strong>The ROKI hosted checkout.<\/strong> The customer goes out to a ROKI page, pays, and comes back. It is the simplest path and it works even if your store has no HTTPS.<\/li>\n<\/ul>\n\n<p>Both behave the same in the classic checkout and in the block checkout.<\/p>\n\n<p><strong>What it does for you<\/strong><\/p>\n\n<ul>\n<li><strong>Refunds and voids from the admin.<\/strong> If the transaction can still be voided, the plugin voids it instead of refunding it: a void never shows up on the customer's card statement.<\/li>\n<li><strong>Automatic reconciliation.<\/strong> Every five minutes it looks at pending orders and asks ROKI about them. If a webhook is lost to a deployment or a network outage, your customer is not left with a stuck order.<\/li>\n<li><strong>Verified webhooks.<\/strong> The signature is checked with HMAC-SHA256 over the raw body and in constant time, and repeated deliveries are discarded by their event id.<\/li>\n<li><strong>A diagnostics button.<\/strong> It checks your configuration end to end - key, environment, webhook, signature - and tells you exactly what is missing, instead of failing only when a customer tries to pay.<\/li>\n<li><strong>Processing fee passed to the customer.<\/strong> An optional switch: ROKI recalculates the total so that your store keeps the order amount.<\/li>\n<\/ul>\n\n<p><strong>What this plugin does NOT do, said plainly<\/strong><\/p>\n\n<ul>\n<li>It does not mark an order as paid because the customer came back from the checkout. Coming back means the browser came back, not that money moved. An order is marked paid by the webhook or by reconciliation.<\/li>\n<li>It does not store card numbers. It never receives them: card entry always happens on a ROKI surface.<\/li>\n<\/ul>\n\n<p><strong>Third-party service: a ROKI account is required<\/strong><\/p>\n\n<p>This plugin connects your store to ROKI Connect, a payment service operated by ROKI, and it does nothing without it. You need a ROKI merchant account to obtain your API keys. Card numbers are never sent by your server: they are typed directly into a ROKI surface.<\/p>\n\n<p>Exactly what is sent, when, and the links to ROKI's terms and privacy policy are in the <strong>External services<\/strong> section below. It is written out there once rather than in two places, so the two cannot drift apart.<\/p>\n\n<ul>\n<li>Service and merchant accounts: https:\/\/roki.la<\/li>\n<li>Technical documentation: https:\/\/connect.roki.la<\/li>\n<\/ul>\n\n<p>Built in Honduras by Danilo Ant\u00fanez.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to <strong>ROKI Connect<\/strong>, the payment API of ROKI Technologies S.A. de C.V., to\ncreate and manage card payments. A ROKI merchant account is required; the plugin does nothing\nwithout one. ROKI is the payment processor, so this connection is what the plugin is for.<\/p>\n\n<p><strong>Every place this plugin reaches out, and from where<\/strong><\/p>\n\n<p>There are exactly four, and all four are ROKI:<\/p>\n\n\n\n\n  Where in the code\n  Address\n  When it happens\n\n\n\n\n  <code>includes\/class-roki-gateway.php<\/code>\n  <code>https:\/\/aura.roki.systems\/api\/connect\/v1<\/code>\n  Server-side. Creating a payment, reading its status, voiding, refunding, fetching a receipt\n\n\n  <code>includes\/class-roki-gateway.php<\/code>\n  <code>https:\/\/aura.roki.systems\/api\/connect\/embed\/confirm<\/code>\n  Server-side. Only in the embedded card-fields mode, to complete a charge from the single-use token\n\n\n  <code>includes\/class-roki-gateway.php<\/code>\n  <code>https:\/\/aura.roki.systems\/connect\/components\/v1\/roki.js<\/code>\n  In the customer's browser, on the checkout page of the classic checkout, only in the embedded card-fields mode\n\n\n  <code>includes\/class-roki-blocks.php<\/code>\n  <code>https:\/\/aura.roki.systems\/connect\/components\/v1\/roki.js<\/code>\n  The same script, for the block checkout\n\n\n\n\n<p>The two server-side calls carry your secret API key. The browser script never does: it is loaded\nwith the publishable key, which cannot charge anything on its own.<\/p>\n\n<p><strong>With the hosted checkout, no ROKI script is loaded on your site at all<\/strong> - the customer goes to a\nROKI page instead. The browser only contacts ROKI when you turn on the card fields inside your own\nstore.<\/p>\n\n<p><strong>What is sent, and when<\/strong><\/p>\n\n<p>Every time a customer places an order and chooses this payment method, the plugin sends the\nfollowing to <code>https:\/\/aura.roki.systems\/api\/connect\/v1<\/code>:<\/p>\n\n<ul>\n<li>the order total, and a label built from the order number, so you can recognise the payment;<\/li>\n<li>the order id, the order key and your store URL, so the payment can be matched back to the order\nwhen ROKI notifies your site;<\/li>\n<li>an expiry time for the payment link;<\/li>\n<li>the return addresses on your store, so the customer comes back after paying;<\/li>\n<li>the billing name, email address and phone number, <strong>only if the customer filled them in<\/strong> at\ncheckout. They prefill ROKI's payment form and are used for the receipt.<\/li>\n<\/ul>\n\n<p>The card number is never sent by the plugin and never reaches your server: the customer types it on\nROKI's own page, or into an iframe served by ROKI, and only a single-use token comes back.<\/p>\n\n<p>The plugin also queries that same API to check the status of pending orders, and to void or refund a\npayment when you ask it to from the order screen.<\/p>\n\n<p><strong>What the browser script does<\/strong><\/p>\n\n<pre><code>roki.js draws the card fields inside an iframe served by ROKI and turns the card into a\n<\/code><\/pre>\n\n<p>single-use token. The card number is entered inside that iframe, on ROKI's domain, so it never\nreaches your page or your server - only the token does, and your server exchanges it for a charge.<\/p>\n\n<p><strong>Terms and privacy<\/strong><\/p>\n\n<ul>\n<li>Terms and Conditions: https:\/\/roki.la\/terms<\/li>\n<li>Privacy Policy: https:\/\/roki.la\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>, or install it from <strong>Plugins &gt; Add New<\/strong>.<\/li>\n<li>Activate it from the <strong>Plugins<\/strong> menu.<\/li>\n<li>Go to <strong>WooCommerce &gt; Settings &gt; Payments &gt; ROKI Connect<\/strong>.<\/li>\n<li>Paste your secret key. It starts with <code>sk_test_<\/code> for testing and with <code>sk_live_<\/code> to charge for real. You will find it in the API integration tab of the ROKI portal.<\/li>\n<li>In the mode selector, labelled <code>Como cobra<\/code>, choose how you want to charge: <code>Checkout de ROKI (el cliente sale de tu tienda)<\/code> sends the customer out to ROKI, and <code>Campos de tarjeta en tu tienda<\/code> draws the card fields inside your own checkout. For the second one you also need the publishable key (<code>pk_test_<\/code> or <code>pk_live_<\/code>) and your store must be served over HTTPS.<\/li>\n<li>Copy the webhook address shown on that screen, register it in the ROKI portal, and paste back the signing secret it gives you.<\/li>\n<li>Press the <code>Ejecutar diagnostico<\/code> button. If every check comes out green, you can start charging.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20the%20plugin%20interface%20in%20english%3F\"><h3>Is the plugin interface in English?<\/h3><\/dt>\n<dd><p>No. The settings, the notices and the customer-facing texts are in Spanish, because ROKI Connect is a Honduran payment gateway and its merchants read Spanish. Only this readme is in English, as the plugin directory requires. That is why the steps above quote the on-screen labels in Spanish: they are what you will actually see.<\/p><\/dd>\n<dt id=\"do%20i%20need%20https%3F\"><h3>Do I need HTTPS?<\/h3><\/dt>\n<dd><p>Not for the ROKI hosted checkout: the payment happens on a ROKI page, which is HTTPS. For the card fields inside your store, yes - ROKI requires the return addresses to be HTTPS. If you have no certificate, the plugin falls back to the hosted checkout on its own and says so in the diagnostics.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20webhook%20is%20lost%3F\"><h3>What happens if a webhook is lost?<\/h3><\/dt>\n<dd><p>Nothing serious. Every five minutes the plugin looks at the orders that are still pending and asks ROKI about each one. A paid order is credited on its own even if the notification never arrived.<\/p><\/dd>\n<dt id=\"can%20i%20refund%20from%20woocommerce%3F\"><h3>Can I refund from WooCommerce?<\/h3><\/dt>\n<dd><p>Yes, from the order. The plugin tries to void first, which is the right thing to do while the transaction has not settled, and refunds it if it can no longer be voided.<\/p><\/dd>\n<dt id=\"which%20currency%20does%20it%20charge%20in%3F\"><h3>Which currency does it charge in?<\/h3><\/dt>\n<dd><p>Honduran lempira (HNL), which is what ROKI Connect processes.<\/p><\/dd>\n<dt id=\"can%20i%20test%20without%20charging%20for%20real%3F\"><h3>Can I test without charging for real?<\/h3><\/dt>\n<dd><p>Yes. With an <code>sk_test_<\/code> key everything works the same against ROKI's sandbox, without moving money.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.7<\/h4>\n\n<ul>\n<li>The External services section now lists, one by one, every address this plugin contacts, which\nfile does it, and under what conditions - including that with the hosted checkout the browser\nnever contacts ROKI at all.<\/li>\n<\/ul>\n\n<h4>1.1.6<\/h4>\n\n<ul>\n<li>Ready for the WordPress.org plugin directory. The text domain now matches the plugin slug, so the\ndirectory can serve translations; the plugin name follows the \"for WooCommerce\" pattern the\ndirectory requires; and this readme is in English. Nothing in the interface changed: the screens,\nthe settings and their labels are exactly the same, in Spanish.<\/li>\n<li>The diagnostics script is registered and attached with <code>wp_add_inline_script()<\/code> instead of being\nprinted as a tag, and its result is built with <code>createElement<\/code> rather than <code>innerHTML<\/code>, because\npart of that text comes from the API response.<\/li>\n<li>Added the <code>Requires Plugins: woocommerce<\/code> header.<\/li>\n<li>The ROKI card script is now enqueued with the plugin version attached, so updating the plugin also\nrefreshes the copy the browser had cached.<\/li>\n<li>The diagnostics button is only drawn for users who can manage WooCommerce. It never granted\nanything by itself - the diagnostics action already checked the capability and rejected anyone\nelse - but it printed its nonce on any admin screen that carried the right query parameter.<\/li>\n<\/ul>\n\n<h4>1.1.4<\/h4>\n\n<ul>\n<li>Fixes a crash that took down the whole site when two ROKI plugins live together. Each one carries\nits own copy of the PHP client, and the second one to load brought WordPress down with a white\nscreen. It showed up when installing the GiveWP donations plugin next to this one, which is a\nnormal combination for a school or a church with a shop. Now the first one to load wins and the\nother reuses it.<\/li>\n<\/ul>\n\n<h4>1.1.3<\/h4>\n\n<ul>\n<li>A payment made in ANOTHER store can no longer mark an order of this one as paid. If you have two\nstores connected to the same ROKI account - a test copy, two brands, or a migration with the old\nstore still plugged in - each one receives the other's notifications, signed with the same secret.\nThe plugin now checks whose payment it is before touching anything.<\/li>\n<\/ul>\n\n<h4>1.1.2<\/h4>\n\n<ul>\n<li>The card fields inside your store are no longer marked as Beta. The mode has already taken real\npayments, 3-D Secure included, and there is no reason for the setting to keep saying otherwise.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Orders taken with the embedded card fields are back in reconciliation and in the query made when\nthe customer returns from the checkout. They used to fall out of both, because both started by\nasking for a numeric id that this mode never produces: if the webhook was lost, the order stayed\npending forever.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>The card fields can live inside your own store: the customer no longer has to go out to the ROKI\ncheckout. You choose it in the settings, under <code>Como cobra<\/code>.<\/li>\n<li>The hosted checkout is still there and is what gets used when the publishable key is missing or\nthe store is not HTTPS.<\/li>\n<li>The diagnostics warns you when you picked the card fields in your store but they are not being\nused, and why.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>The API client records the warnings ROKI returns when it ignores a field.<\/li>\n<li>The automatic update check tolerates a manifest with a BOM, which used to make it fail silently.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Classic and block checkout.<\/li>\n<li>Signed webhooks with deduplication by event id.<\/li>\n<li>Voids and refunds from the admin.<\/li>\n<li>Automatic reconciliation every five minutes.<\/li>\n<\/ul>","raw_excerpt":"Accept credit and debit cards in Honduran lempira with ROKI Connect, using the hosted checkout or card fields inside your own store.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358677"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rokiconnect"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358677"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358677"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358677"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358677"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358677"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}