AI agents are already shopping your store. ChatGPT browses product pages, agentic checkouts are rolling out across the ecosystem. AVA Pay tells you which agents to trust, lets you set the rules, and records every verification and attributed order so you can see the traffic when reporting lands.
This plugin connects your WooCommerce store to the AVA Pay verification API, which cryptographically verifies agent traffic across protocols (Visa Trusted Agent Protocol, IETF Web Bot Auth, Google AP2) through a single endpoint.
What it does
/wp-json/ava-pay/v1/verify-agent) that proxies signed agent requests to the AVA Pay API. Signatures are verified server-side against the agent platforms’ published keys.Trust model, honestly stated
unverifiable rather than as a rejection, and the storefront response says verification_unavailable instead of agent_blocked.This plugin connects to the AVA Pay verification API, operated by Agentic Verification Architecture LLC, to check whether an AI agent’s signed request is genuine. Your store cannot verify agent signatures on its own; this API does the cryptographic check against the agent platforms’ published keys.
POST https://pay.avalayer.com/verify. The base URL is the “AVA Pay API URL” setting (default https://pay.avalayer.com) and can also be changed with the ava_pay_api_url filter./wp-json/ava-pay/v1/verify-agent, and passes the local rate limit. That endpoint is how signed agent requests reach the plugin, either directly from the agent or from the storefront script on a page view that carries agent signature parameters. The plugin forwards each such request, with only the headers listed below, and lets the API decide; a request without valid signature material is rejected there. Nothing is sent on ordinary page views, in the admin, or during checkout.Signature, Signature-Input and Signature-Agent, every header the agent’s signature names as covered, the protocol headers the verifier reads by name (X-Ava-Mandate, X-Ava-Discount-Hint, the AP2 mandate headers, Content-Digest, and Content-Type when there is a body), and Host, replaced by your site’s own host; and the request body, if there is one. Every other header is dropped before the request leaves your site, including X-Forwarded-For and User-Agent (unless the agent’s signature covers it). Cookie, Authorization, Proxy-Authorization and X-WP-Nonce are never forwarded, even when the agent’s signature covers them.Terms of service: https://avalayer.com/terms
Privacy policy: https://avalayer.com/privacy