Condixia – REST Gateway

Condixia – REST Gateway

Details
View on WordPress

Condixia – REST Gateway provides authenticated and controlled REST access to WordPress content and selected WooCommerce data for external applications.

It is designed for developers building applications such as Laravel dashboards, headless frontends, mobile applications, internal tools, reporting systems, and SaaS integrations that use WordPress as a backend.

Condixia uses its own API client and credential system. External applications do not need WordPress user passwords, login cookies, Application Passwords, WooCommerce consumer keys, JWT plugins, or OAuth plugins.

Core Features

  • Secure Condixia API clients and Bearer credentials.
  • API credentials are stored as hashes rather than reusable plaintext secrets.
  • API secrets are displayed only when initially created.
  • Per-client scopes and permissions.
  • Credential expiration, disabling, and revocation.
  • Versioned REST namespace using condixia/v1.
  • Read access to posts, pages, and supported public custom post types.
  • Explicitly controlled create and update access for supported WordPress content.
  • Write operations are disabled by default per resource.
  • Read-only WooCommerce product access.
  • Read-only WooCommerce order access.
  • WooCommerce HPOS-compatible order access using supported WooCommerce APIs.
  • Pagination, searching, filtering, sorting, and field selection where supported.
  • Basic per-client rate protection.
  • Resource schemas that prevent unrestricted field and metadata exposure.
  • Endpoints documentation inside WordPress Admin.
  • API client management inside WordPress Admin.
  • No DELETE operations in the Free edition.

Security Model

Condixia separates authentication from authorization.

Authentication determines which Condixia API Client is making the request.

Authorization determines which resources and operations that client may access.

Successfully authenticating does not automatically grant unrestricted access.

Resources expose explicitly defined fields rather than raw WordPress or WooCommerce objects. Arbitrary post metadata, authentication data, session information, API secrets, and other protected internal values are not exposed by default.

WordPress content writes use supported WordPress APIs. WooCommerce order and product access uses supported WooCommerce APIs.

Authentication

External applications authenticate using an HTTP Bearer credential:

Authorization: Bearer cxi_v1_<client-id>.<secret>

The plaintext secret is shown only when the API client is created.

Store API credentials securely in your external application.

Production API requests should use HTTPS.

Example Request

Retrieve WordPress posts:

GET /wp-json/condixia/v1/resources/posts

Example cURL request:

curl -H "Authorization: Bearer <your-api-key>" "https://example.com/wp-json/condixia/v1/resources/posts"

Retrieve a specific post:

GET /wp-json/condixia/v1/resources/posts/123

Retrieve WooCommerce products:

GET /wp-json/condixia/v1/resources/products

Retrieve WooCommerce orders:

GET /wp-json/condixia/v1/resources/orders

Available resources depend on the active WordPress post types, installed plugins, WooCommerce availability, resource configuration, and the API client’s assigned scopes.

Third-Party Libraries

Condixia – REST Gateway includes Select2 for searchable multi-select controls in the WordPress administration interface.

Select2
Version: 4.1.0
License: MIT
Project: https://select2.org/
Source: https://github.com/select2/select2

The Select2 license is included with the bundled library.

Details

Plugin code:
condixia-rest-gateway
Plugin version:
0.1.0
Author:
Outdated:
No
WP version:
6.2 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-09-28
Rating:
Times rated:
0
api
developer-tools
headless
rest-api
woocommerce