Integrations5 min read

Connecting WooCommerce

Connect your WooCommerce store to Symbi so your support agents can look up orders, customers, and products during ticket handling.

What WooCommerce Enables

Once connected, an agent can look up order, customer, and product data from your WooCommerce store while it works on a support ticket, and use what it finds in the reply or summary it produces. It is a read-only integration: no orders, customers, or products are created or changed.

WooCommerce is a data source only — it cannot trigger an agent. Your agents are still triggered by your existing support channel, such as FreshDesk, Zoho Desk, or Gmail.

Prerequisites

Before connecting, you need:

  • A WooCommerce store on a public domain, served over HTTPS
  • WordPress permalinks set to anything other than Plain — the /wp-json/ REST routes only exist with pretty permalinks
  • A WooCommerce Consumer Key and Consumer Secret with Read permission
  • Any firewall or security plugin (Wordfence, Cloudflare rules) configured to allow requests from Symbi

Generate the keys in your WooCommerce admin:

  1. If you don't have one already, create a dedicated Shop Manager user under Users → Add New. The key belongs to a user, and it should not be your own admin account
  2. Go to WooCommerce → Settings → Advanced → REST API
  3. Click Add key
  4. Set User to that Shop Manager user and Permissions to Read
  5. Click Generate API key and copy the Consumer Key and Consumer Secret immediately — the Secret is shown only once

Connect Your Store

  1. Open Settings → Connectors and click the WooCommerce tile
  2. Click Configure WooCommerce
  3. Enter:
    • Store URL — your shop's address as it resolves in a browser (https://shop.example.com). Use the exact URL including www or non-www, as it redirects
    • Consumer Key — starts with ck_
    • Consumer Secret — starts with cs_
  4. Click Connect. Symbi verifies the credentials against your store's REST API and only saves them if the check passes — there is no separate save step. If verification fails, nothing is stored and the error names what to change

Only Owner and Admin users can configure connectors.

Register the Store as a Resource

Connecting stores your credentials; it does not yet give an agent anything to bind to. Register the store itself:

  1. On the WooCommerce connector page, click Discover more under Registered resources
  2. Confirm the store that appears and register it

Symbi registers the store as a single resource — there is nothing else to enumerate, since every tool reads the same store. You can also do this from an agent: on its Apps card, click Find more… on the WooCommerce row.

Assigning WooCommerce to an agent is a draft change. It takes effect only when you publish the agent — see Managing Agents.

What Your Agent Can Do

When an agent handles a support ticket, it can:

  • Look up an order by number — status, dates, line items, shipping method, and any tracking information
  • Search the customer's orders — by status or date range, newest first
  • Get a customer's account summary — order history for registered customers
  • Look up a product — by id, SKU, or name: price, stock status, and store link

How Order Lookups Are Scoped

Order numbers in WooCommerce are sequential and guessable, so order reads are tied to a customer email server-side — never by a rule in the agent's prompt:

  • On a run triggered by a customer message, the identity is the verified sender of that message. The agent cannot widen it: the ticket text cannot change whose orders it sees, and if the sender's address cannot be resolved the lookup is refused rather than guessed
  • On a manual or operator-initiated run, your own staff name the customer, so the lookup returns whichever customer's orders they ask for
  • Product lookups are not customer-scoped — products are public catalogue data

Security

Your Consumer Key and Consumer Secret are encrypted with AES-256 before being stored. The WooCommerce integration ships read tools only — there is no tool that creates or updates anything in your store. The key's own permission scope is set by you in WooCommerce, so generating it with Read permission is what makes writes impossible at the source. You can revoke the key from WooCommerce at any time and generate a new one.

Warning

Use a dedicated key with Read permission on a Shop Manager user — not your own admin credentials. If the key is ever leaked, that limits what it exposes, and you can revoke it without disturbing your own access.

Troubleshooting

If the connection fails at Connect, the error names the cause:

  • Rejected key or secret (401) — check the key still exists under WooCommerce → Settings → Advanced → REST API with Read permission, and that the store is served over HTTPS
  • Refused request (403) — a firewall or security plugin (Wordfence, Cloudflare rules) is likely blocking Symbi. Ask whoever manages the store to allow Symbi's egress IP
  • REST API not found (404) — check the store URL, and that WordPress permalinks are not set to Plain. The /wp-json/ routes need pretty permalinks

Limitations

  • Read-only — agents cannot create or update orders, customers, or products
  • Support channel required — WooCommerce cannot be a trigger source; an agent using it still needs FreshDesk, Zoho Desk, Gmail, or another trigger integration
  • Company integration — not available for the Personal Assistant

What's Next?