WordPress + WooCommerce
Integrate your shop with ShopBridge.
Install the merchant plugin, expose an opt-in catalog, and prepare your staging shop for the supervised testnet pilot. This is not a self-service production payment launch.
Requirements
- WordPress 6.4 or later (plugin metadata: tested up to 7.1).
- PHP 8.1 or later and an active WooCommerce installation.
- A public HTTPS site with a staging product, shipping and tax configuration.
Download the WooCommerce plugin
Download agentcart-shopbridge.zip
- Release version
- 1.24.0
- Size
- 133304 bytes
- SHA-256
22f5133dae86a4f2cd3e69bd5033f9448b46920649cd4683d65450f1ae80619c
Verify the downloaded file and compare the result with the SHA-256 above:
shasum -a 256 agentcart-shopbridge.zip
The ZIP contains agentcart-shopbridge/. Downloads are hosted by GitHub. View this release’s checksum manifest.
Install and configure in WordPress
- Open Plugins → Add New → Upload Plugin, select the ZIP, install it, and activate AgentCart ShopBridge.
- Open WooCommerce → AgentCart. If credentials are not managed in
wp-config.php, use the Quick Start panel to prepare sandbox access defaults. This does not expose products or configure a payment recipient. - Configure a stable merchant id, support email, payment recipient or Stripe profile, verifier URL and token, checkout mode, signed-request policy and product exposure mode. Use Credential Actions to generate or rotate locally managed tokens.
- Add normal WooCommerce products. Expose only the intended products, preview product exposure, review the catalog diff and save a current catalog snapshot.
- In Registry Proof, refresh metadata when identity, payment settings or exposed categories change. Run the public endpoint check.
- Run the sandbox quote check and guided admin dry checkout. The dry run tests the WooCommerce quote/order path and cleans up its test records; it does not call the live verifier, move funds or prove settlement.
- Complete supervised registry enrollment below. Have the observer verify finalized inclusion, then select Check registry health.
- Run a separate buyer test with the configured external verifier before claiming testnet settlement. Use Support Diagnostics for a redacted setup report.
Configuration essentials for production readiness
The setup checklist is a readiness gate, not a statement that the current pilot is production-ready.
- Set stable merchant identity, a public support contact, terms and returns URLs.
- Configure WooCommerce tax, shipping zones and allowed destination countries. Review excluded and restricted products and quantity limits.
- Configure the selected payment destination and an external verifier URL and token. Use
external_verifier_onlycheckout mode. - Choose the signed-request policy for sensitive endpoints. Shared secrets must have at least 32 characters and be distinct for merchant, verifier and signed-request roles.
- Publish and check the HTTPS manifest, registry proof, revocations and bundle; confirm the exact finalized registry record rather than relying on a hosted submission.
Payment verification is a separate service
The external verifier image is ghcr.io/giraeffleaeffle/agentcart-shopbridge-verifier. An operator runs the verifier and configures its rail-specific credentials and payment profile, then sets its URL and token in the plugin. See the verifier contract and integration requirements.
With external_verifier_only, a trusted merchant token cannot bypass payment verification to mark a demo order paid. The verifier must bind the receipt to amount, currency, merchant destination, quote hash, payment contract hash and a replay-safe transaction reference.
| Rail | Current scope | Availability |
|---|---|---|
| Tempo MPP | USD quotes; pathUSD on Tempo Moderato testnet. No EUR conversion. | Testnet verification. Included in release 1.24.0. |
| Stripe/card MPP | Sandbox verifier for quote-bound card credentials and merchant profiles. | Sandbox only in the current pilot. Included in release 1.24.0. |
| x402 v2 exact | USD quotes and Base Sepolia USDC; verified on staging. Disabled by default. | In the next release, not in the 1.24.0 downloads. Requires an explicit verifier capability check. Refunds are manual only. |
| EUR stablecoins | EUR-native settlement and quote-bound FX. | Future work, not a current rail. |
What the plugin does not do
The plugin moves no money. Settlement and rail refunds belong to the buyer’s wallet or provider and the merchant’s configured verifier. WooCommerce stays the system of record for products, stock, tax, shipping, fulfillment, refunds and support. The merchant stays merchant of record.
External services
Public catalog and quote browsing does not contact a verifier or hosted registry connection. Paid-order and verified-refund operations can send quote, receipt and order/refund data to the merchant-configured verifier. Registry submission, revocation and health actions can send public merchant records and endpoint metadata to the merchant-configured registry connection.
An administrator’s registry health action makes read-only calls to https://rpc.moderato.tempo.xyz using public on-chain identity and registry state, not wallet secrets or buyer/order data. The services’ terms and privacy policies must be reviewed by the operator. A hosted registry response is diagnostic; it is not proof of finalized on-chain inclusion.
Get listed in the on-chain registry
Enrollment is a supervised Tempo Moderato pilot. A pilot observer prepares and reviews the transaction; the merchant’s own external controller wallet signs it. WordPress stores only four public fields:
- Public controller address.
- On-chain registry chain (CAIP-2 identifier).
- On-chain registry contract address.
- On-chain registry record id.
After saving these fields, refresh the metadata and public endpoint check. Review the observer’s exact zero-value transaction plan in your own wallet. The observer verifies the exact transaction and active record at a finalized block; then run the plugin’s registry health check. Never enter a private key, seed phrase, wallet session or signature into WordPress.
The registry controller is a separate role from the merchant’s payment recipient. Read the supervised enrollment procedure.
Public discovery and commerce endpoints
These paths belong to your merchant’s HTTPS origin, not to agentcart.eu:
/.well-known/agentcart.json— merchant manifest./.well-known/agentcart-registry-proof.json— domain proof./.well-known/agentcart-registry-revocations.json— revocation document./.well-known/agentcart-registry-bundle.json— onboarding bundle./.well-known/agentcart-registry-records/{sha256}.json— content-addressed record./wp-json/agentcart/v1/catalog— exposed catalog./wp-json/agentcart/v1/quote— WooCommerce-backed quotes.
Order creation uses /wp-json/agentcart/v1/orders; status uses /wp-json/agentcart/v1/orders/{id}/status with an order token. Refund and cancellation routes under the order require a merchant token or trusted gateway; they are not public buyer actions. Support diagnostics and checkout recovery require WooCommerce manager permissions. Signed-request policy can further restrict sensitive calls.
Optional Kubernetes deployment
For operators who already use Kubernetes, the repository provides an optional single-store Helm chart. A normal WordPress plugin installation does not require Helm.
Join the supervised pilot
Email contact@agentcart.eu with your staging shop and integration questions. The pilot is testnet and sandbox only; no real money moves.