← All integrations
WordPress plugin 1.0.0

WooCommerce, openly documented.

The widget plugin and signed order connection are two separate integrations. The plugin installs the chat. The order connection reads verified orders through the WooCommerce REST API.

Development installation

The release candidate includes a zip file and reproducible verification script.

Platform review

Submitted to WordPress and awaiting approval.

Public listing

Not published in the WordPress directory. The signed zip is a separate distribution route.

01 / From zero to widget

Installation

Download saazly-chat.zip from the distribution route specified by Saazly.

Open Plugins in WordPress Admin, select Add New Plugin and Upload Plugin.

Install the zip file and activate Saazly Chat.

Open Settings and Saazly Chat. Paste in the Widget ID from Saazly and save.

Open the public storefront and check that the chat button appears.

For order retrieval, a WooCommerce admin creates a REST API key with read permission and connects the store under Settings and Order connections in Saazly.

02 / Minimum access

Permissions and scopes

WordPress permission

Only users with manage_options can change the Widget ID.

Widget plugin

The plugin requires no special WooCommerce permission and does not use REST API keys.

Order connection

The separate server connection uses a WooCommerce REST API key with read permission. Saazly does not write order, payment, fulfilment or customer data.

Customer matching

An email address or order number alone never produces a verified match. The order number must be combined with a name or email address that matches the provider order.

03 / Data contract

Data read and written

Read locally

The saved public Widget ID. The settings page can read the widget's public name from Saazly.

Written locally

A single WordPress option value containing the public Widget ID.

Browser-reported cart

The widget can read products, quantities, prices and currency from the visitor's current cart. This is behavioural context, not verified order data.

Provider-verified order

Order id, customer-facing order number, amount, currency, payment status, fulfilment status, deliveries, provider timestamps, data source and freshness are read by the server adapter.

04 / Events

Webhooks

The plugin has no webhooks

Version 1.0.0 of the widget plugin does not register or receive any webhooks.

Signed order webhooks

The server connection registers order.created and order.updated. Each delivery is verified with HMAC SHA 256, deduplicated using the delivery id and reconciled against the provider's modified time.

Reconciliation

A signed server run reads changed orders from WooCommerce and recovers missed webhooks without older events overwriting newer data.

Widget traffic

The loaded widget uses Saazly's public widget configuration and chat service in accordance with Saazly's privacy policy.

05 / Secrets

Token storage

The plugin stores no tokens

The widget plugin stores no access tokens, refresh tokens, API keys or passwords.

Encrypted server credentials

The consumer key, consumer secret and webhook secret are encrypted with AES 256 GCM before being written to the database. Authenticated clients have no table access to the values.

Widget ID

Widget ID is a public identifier and is stored as a WordPress option value.

06 / Clean removal

Uninstallation

Deactivate Saazly Chat under Plugins.

Delete the plugin if you want to remove it completely.

On deletion, uninstall.php removes the saazly_chat_widget_id option key from a standard installation, from every site in WordPress multisite and from the network's site options.

Browser data clean-up is governed by Saazly's standard data deletion process and is not affected by removing the WordPress files.

The order connection is disabled separately in Saazly. Encrypted credentials are cleared, local access is blocked and registered order webhooks are removed in WooCommerce when the store responds.

07 / When something goes wrong

Troubleshooting

Widget ID is not accepted

Copy the full UUID value from Saazly. Spaces are removed, but an incomplete value will not be saved.

The widget does not appear

Check that the plugin is active, the Widget ID is saved and the page's Content Security Policy allows cdn.saazly.com.

Verification cannot reach Saazly

The Widget ID is saved even if the name check temporarily fails. Check outbound HTTPS from the WordPress server.

The order connection is rejected

Check that the key has read permission, the HTTPS address is exact and the system status shows the same site address.

The order is not up to date

Check the integration status in Saazly. Webhook replay is safe, and reconciliation retrieves orders changed since the latest cursor.

Still stuck?

Send the store domain, time, and error message. Never send tokens or passwords.

Contact support
WooCommerce integration | Saazly documentation