The release candidate includes a zip file and reproducible verification script.
Installation
Download saazly-chat.zip from the distribution route specified by Saazly.
Open Plugins in WordPress Admin, select Add New Plugin and Upload Plugin.
Install the zip file and activate Saazly Chat.
Open Settings and Saazly Chat. Paste in the Widget ID from Saazly and save.
Open the public storefront and check that the chat button appears.
For order retrieval, a WooCommerce admin creates a REST API key with read permission and connects the store under Settings and Order connections in Saazly.
Permissions and scopes
Only users with manage_options can change the Widget ID.
The plugin requires no special WooCommerce permission and does not use REST API keys.
The separate server connection uses a WooCommerce REST API key with read permission. Saazly does not write order, payment, fulfilment or customer data.
An email address or order number alone never produces a verified match. The order number must be combined with a name or email address that matches the provider order.
Data read and written
The saved public Widget ID. The settings page can read the widget's public name from Saazly.
A single WordPress option value containing the public Widget ID.
The widget can read products, quantities, prices and currency from the visitor's current cart. This is behavioural context, not verified order data.
Order id, customer-facing order number, amount, currency, payment status, fulfilment status, deliveries, provider timestamps, data source and freshness are read by the server adapter.
Webhooks
Version 1.0.0 of the widget plugin does not register or receive any webhooks.
The server connection registers order.created and order.updated. Each delivery is verified with HMAC SHA 256, deduplicated using the delivery id and reconciled against the provider's modified time.
A signed server run reads changed orders from WooCommerce and recovers missed webhooks without older events overwriting newer data.
The loaded widget uses Saazly's public widget configuration and chat service in accordance with Saazly's privacy policy.
Token storage
The widget plugin stores no access tokens, refresh tokens, API keys or passwords.
The consumer key, consumer secret and webhook secret are encrypted with AES 256 GCM before being written to the database. Authenticated clients have no table access to the values.
Widget ID is a public identifier and is stored as a WordPress option value.
Uninstallation
Deactivate Saazly Chat under Plugins.
Delete the plugin if you want to remove it completely.
On deletion, uninstall.php removes the saazly_chat_widget_id option key from a standard installation, from every site in WordPress multisite and from the network's site options.
Browser data clean-up is governed by Saazly's standard data deletion process and is not affected by removing the WordPress files.
The order connection is disabled separately in Saazly. Encrypted credentials are cleared, local access is blocked and registered order webhooks are removed in WooCommerce when the store responds.
Troubleshooting
Copy the full UUID value from Saazly. Spaces are removed, but an incomplete value will not be saved.
Check that the plugin is active, the Widget ID is saved and the page's Content Security Policy allows cdn.saazly.com.
The Widget ID is saved even if the name check temporarily fails. Check outbound HTTPS from the WordPress server.
Check that the key has read permission, the HTTPS address is exact and the system status shows the same site address.
Check the integration status in Saazly. Webhook replay is safe, and reconciliation retrieves orders changed since the latest cursor.
Send the store domain, time, and error message. Never send tokens or passwords.