KartoDesk gives your team one fast screen for daily order work, without leaving WordPress.
KartoDesk uses WooCommerce’s own REST API inside your site as the signed-in user. It needs no API keys, stores no data of its own beyond tracking on the order, and makes no requests to external services.
Administrators always have full access, and Shop managers start with full access. Under KartoDesk > Settings, administrators choose what each other role can do: view orders, change order status, add private notes, notify customers, manage shipment tracking, view products, edit products, change stock, view customers, view reports, open settings, issue refunds, manage discounts, edit customers and run maintenance tools. Permissions are standard WordPress capabilities (prefixed kartodesk_), so role-editor plugins can manage them as well. WooCommerce’s own permission checks still apply to every request.
Customer-facing notes are sent by WooCommerce’s Customer note email to the order’s billing email, if that email is enabled under WooCommerce Settings Emails. KartoDesk reports only that WooCommerce accepted the note; it cannot confirm delivery. Changing an order status can also trigger WooCommerce’s own status emails.
The JavaScript in build/ is compiled from TypeScript and React source in the public repository: https://github.com/shantz1/wooops (the panel components are in src/, the plugin entry in wordpress/). Build it with npm ci && npm run build:wp.
KartoDesk does not track users or send telemetry. Its own scripts and styles load locally; product images can use the store’s image or CDN URLs. It displays customer details that WooCommerce already stores, only to users who can manage WooCommerce.