AI shopping agents are starting to browse and buy on their own. They do not see your store the way a person does: they read your catalog, your structured data and your policy pages, and they give up quietly when something does not answer the way they expect. The store owner sees a site that works perfectly in a browser and has no idea anything is wrong.
AgentShoppable runs the exact sequence a shopping agent runs against your live storefront — find the store, read the catalog, search it, pick a variant, create a cart, reach checkout — and tells you where it broke.
Most of that works from the outside, with no plugin at all. This plugin exists for the handful of things a public storefront does not expose:
It has no scheduled tasks, no background requests and no telemetry. It only answers requests that arrive carrying a valid signature made with a key you generated. Installing it and generating a key sends nothing anywhere. Data leaves your site only when you paste that key into AgentShoppable and start a scan.
Every request must carry a timestamp and an HMAC-SHA256 signature over the timestamp, the route and the raw request body, computed with the connection key. Signatures are compared in constant time and requests more than five minutes old are rejected, so a captured request cannot be replayed.
The plugin deliberately does not accept WordPress logins, cookies or Application Passwords for these routes. A stolen admin session cannot read your private product fields or change anything through this plugin. Only the connection key can, and you can rotate or delete it at any time from WooCommerce AgentShoppable.
Fixes are limited to a fixed list of fields in the plugin’s own code — product description, short description, SKU, barcode, weight, and image alt text. A request cannot name an arbitrary meta key, run code, or touch orders, customers, users, settings or prices.
All under /wp-json/agentshoppable/v1:
GET /ping — unsigned. Says only that the plugin is installed and whether a key is set.GET /info — signed. Versions, theme, active plugins, currency, country, store-visibility flags.GET /policies — signed. The pages WooCommerce and WordPress designate as refund, terms, privacy and shipping.GET /product/{id}/private — signed. Barcode, alt text, stock and weight for one product.POST /fix — signed. Applies one approved change and returns the previous value.This plugin is the store’s half of a connection to AgentShoppable, a service operated by Sela Ventures LLC.
What the plugin sends on its own: nothing. It makes no outbound requests. It has no cron jobs and no telemetry, and it does not phone home to check licences or report usage.
What AgentShoppable reads from your site, and when. Only after you generate a connection key here and paste it into your AgentShoppable account, and only while a scan or an approved fix is running, AgentShoppable calls the signed endpoints listed above. Across those calls it can read: your WordPress, WooCommerce and PHP versions; your active theme and the list of active plugin files; your store currency and base country; whether your store is set to coming-soon or private; the title, URL and text of your published refund, terms, privacy and shipping pages; and, for products it is checking, the barcode, SKU, stock quantity, weight, image URLs and image alt text.
It does not read orders, customers, users, payment settings or any personal data, and this plugin exposes no route that could return them.
When you approve a fix, AgentShoppable sends the new value for one whitelisted product field, and this plugin writes it and stores the previous value on your site so the change can be undone.
Service terms: https://agentshoppable.com/terms
Privacy policy: https://agentshoppable.com/privacy
Using the service requires an AgentShoppable account. The plugin is free and GPL-licensed; the service has a free tier and a paid tier.