Linux 软件免费装
Banner图

Counterhand MCP for WooCommerce — AI Agent Server for Claude, ChatGPT & Cursor

开发者 mirumd
更新时间 2026年9月12日 05:45
捐献地址: 去捐款
PHP版本: 8.2 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

woocommerce chatgpt claude mcp mcp-server

下载

1.3.0 1.2.2

详情介绍:

Counterhand MCP connects your WooCommerce store to AI assistants through the Model Context Protocol (MCP) — with security as the first-class feature. It is free, open source (GPL) and self-hosted: nothing about your store passes through a third-party service. Home page and documentation: counterhand.app. Your store gets a clean MCP endpoint at https://yourstore.com/mcp. Assistants connect through a browser consent flow (OAuth 2.1) — no tokens to copy. When an assistant connects, your browser opens a consent screen where you, as a store administrator, choose exactly what it may do and approve. What you can ask an assistant to do Once connected, an AI agent works your store through plain requests, and the Chat tab gives you the same as an in-admin chatbot. What the tool groups cover, in everyday terms: 127 tools, in groups you switch on individually Every group is a separate switch in Settings, with read and write as separate axes. A fresh install exposes Products, Orders and Reports, read-only — everything else is off until you turn it on, and upgrading never widens what your store exposes. Tools delegate to WooCommerce's own REST controllers, so validation, stock handling and HPOS compatibility behave exactly like the standard API. Their input schemas are read from those controllers at runtime rather than copied into this plugin, so a WooCommerce update that adds a field surfaces it automatically, and one that removes a field cannot leave a tool advertising it. Each tool offers the ten or so fields that matter rather than all hundred WooCommerce declares, which keeps assistants accurate. When one of the rest is needed, describe_woocommerce_fields returns the full list for any tool — and writes accept those extra fields directly. Visibility is decided by WooCommerce too: before a tool is offered, this plugin runs WooCommerce's own permission check for that endpoint. A shop manager therefore sees a different set of tools from an administrator, without this plugin keeping a list of who may do what. Two ways to use AI with your store Chat with your store, inside WooCommerce. Ask questions in plain language from wp-admin and the assistant looks the answer up with the same tools an outside app would use. A change that is not easily undone stops and waits for your Approve button — the model cannot wave it through on its own. On WordPress 7.0 and later it uses the AI model WordPress already manages under Settings → Connectors, so this plugin never handles an API key. On older WordPress, connect Claude, ChatGPT, Gemini or a local Ollama model with your own key — the Chat tab tests it before saving, so a wrong key is caught immediately. Connect AI apps you already use. The Connect AI apps tab shows one URL to paste into Claude, ChatGPT, Claude Code or any other MCP client — one click installs it into Cursor and VS Code. There is no token to create and nothing to copy back: the app identifies itself with its own published address (CIMD), and you approve exactly what it may do on a consent screen in your browser. No local proxy, no Node.js required. How this differs from WooCommerce's built-in MCP WooCommerce ships an experimental MCP server behind a feature flag, authenticated with REST API keys and covering a handful of product and order abilities. Counterhand adds what a self-hosted store still lacks: OAuth 2.1 browser consent instead of copied keys, the whole WooCommerce and WordPress surface (coupons, customers, reports, shipping, tax, settings, posts and pages), per-connection scopes with one-click revocation, confirmation-gated risky writes, an audit log, and the in-admin chat. The two can run side by side. Free, open source, sponsor-supported Counterhand is free for every store, with no paid tier and no locked features. Development and support are funded by GitHub Sponsors. The source is on GitHub — issues and pull requests are welcome. Privacy The plugin contacts no server of its own, collects no usage data and phones no telemetry home. It makes no outbound request until you ask it to — see the "External services" section below for exactly which services can be contacted, what is sent and when. Nothing is sent to the author of this plugin, ever.

安装:

  1. In wp-admin go to Plugins → Add New, search for "Counterhand MCP" and click Install, then Activate. WooCommerce must already be active.
  2. Open WooCommerce → Counterhand MCP. On the Settings tab switch on the tool groups your assistants may use — Products, Orders and Reports are on, read-only, by default.
  3. On the Connect AI apps tab copy the endpoint URL (https://yourstore.com/mcp) into Claude, ChatGPT, Claude Code, Cursor or VS Code — or use the one-click install buttons.
  4. Approve the connection on the consent screen that opens in your browser. It appears on the Connections tab, where you can revoke it at any time.
Your store must be reachable over HTTPS from the public internet for cloud assistants (Claude, ChatGPT); Claude Code, Cursor and VS Code connect from your own machine and work with a local site too.

屏幕截图:

  • Connect AI apps — one endpoint URL for Claude, ChatGPT, Cursor, VS Code and Claude Code, with a reachability check.
  • Chat — ask your store questions in plain language from wp-admin, on a model WordPress manages or your own key.
  • Action log — every tool call, with personal data masked before it is stored.

升级注意事项:

1.3.0 Risky changes from the Chat tab now wait for your approval. Security hardening of the OAuth consent flow and tested with WooCommerce 11.1. Connected assistants keep working; apps that can refresh will start doing so on their next connection.

常见问题:

Is it really free?

Yes. Every tool, the chat, OAuth and the action log are in the one free plugin, licensed GPLv2 or later. There is no Pro version and nothing is unlocked by paying. If it saves you time, you can support its maintenance through GitHub Sponsors.

How does an assistant connect?

Add the endpoint URL (https://yourstore.com/mcp) to your MCP client — no token needed. The client discovers the OAuth authorization server, opens your browser to a consent screen, and you approve which scopes it may use. Approved assistants appear on the Connections tab.

The endpoint or discovery documents return 404 or 403

Two causes: (1) pretty permalinks — the endpoint is also available at /wp-json/counterhand/v1/mcp, and re-saving Settings → Permalinks refreshes rewrite rules; (2) some servers block /.well-known/ paths. OAuth discovery lives at /.well-known/oauth-protected-resource, so your server must allow that path. On nginx, add before any dotfile-deny rule: location ^~ /.well-known/ { try_files $uri $uri/ /index.php?$args; }

Which AI clients work?

Any MCP client implementing the current authorization spec (OAuth 2.1 + PKCE + Protected Resource Metadata, with CIMD client identity): Claude on web, mobile and desktop, ChatGPT, Claude Code, Cursor, VS Code, and others.

Claude or ChatGPT cannot see my store

Those apps connect from the vendor's own servers, not from your browser, so your store has to be reachable from the public internet over HTTPS. A local development site works fine with Claude Code, Cursor and VS Code, which connect from your own machine. The Connect AI apps tab checks this for you and says which of the two situations you are in.

An assistant says a tool does not exist

Three things have to agree before a tool is callable: the group is switched on in Settings, the connection was granted that scope on the consent screen, and WooCommerce's own permission check passes for the logged-in owner of the connection. If any one of them says no, the tool is invisible and uncallable — it is never merely hidden. Check the Settings tab first, then the connection's scopes on the Connections tab.

Can an assistant break my store?

The things that could are gated separately. Store settings, payment gateways and system maintenance are their own groups, off by default, sitting behind a collapsed Advanced heading that is never pre-ticked; each of their write tools requires an explicit confirmation; and the maintenance routines that cannot be undone are refused whatever an assistant sends. Calls to those three groups are recorded in the action log even if you have logging switched off.

Can I connect a client that only supports bearer headers?

The security model is OAuth-first. If you need a raw bearer token for a script or CI job, use the counterhand_rate_limit and related filters documented in the plugin, or open an issue on GitHub — a developer token path may be added.

Where do I report a bug or a security issue?

Bugs and feature requests: the GitHub issue tracker or the support forum here. Security issues: please report them privately as described in the repository's SECURITY.md rather than in a public thread.

更新日志:

1.3.0 1.2.2