| 开发者 | mirumd |
|---|---|
| 更新时间 | 2026年9月12日 05:45 |
| 捐献地址: | 去捐款 |
| PHP版本: | 8.2 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
https://yourstore.com/mcp. Assistants connect through a browser consent flow (OAuth 2.1) — no tokens to copy. When an assistant connects, your browser opens a consent screen where you, as a store administrator, choose exactly what it may do and approve.
describe_woocommerce_fields returns the full list for any tool — and writes accept those extra fields directly.
Visibility is decided by WooCommerce too: before a tool is offered, this plugin runs WooCommerce's own permission check for that endpoint. A shop manager therefore sees a different set of tools from an administrator, without this plugin keeping a list of who may do what.
Two ways to use AI with your store
Chat with your store, inside WooCommerce. Ask questions in plain language from wp-admin and the assistant looks the answer up with the same tools an outside app would use. A change that is not easily undone stops and waits for your Approve button — the model cannot wave it through on its own. On WordPress 7.0 and later it uses the AI model WordPress already manages under Settings → Connectors, so this plugin never handles an API key. On older WordPress, connect Claude, ChatGPT, Gemini or a local Ollama model with your own key — the Chat tab tests it before saving, so a wrong key is caught immediately.
Connect AI apps you already use. The Connect AI apps tab shows one URL to paste into Claude, ChatGPT, Claude Code or any other MCP client — one click installs it into Cursor and VS Code. There is no token to create and nothing to copy back: the app identifies itself with its own published address (CIMD), and you approve exactly what it may do on a consent screen in your browser. No local proxy, no Node.js required.
How this differs from WooCommerce's built-in MCP
WooCommerce ships an experimental MCP server behind a feature flag, authenticated with REST API keys and covering a handful of product and order abilities. Counterhand adds what a self-hosted store still lacks: OAuth 2.1 browser consent instead of copied keys, the whole WooCommerce and WordPress surface (coupons, customers, reports, shipping, tax, settings, posts and pages), per-connection scopes with one-click revocation, confirmation-gated risky writes, an audit log, and the in-admin chat. The two can run side by side.
Free, open source, sponsor-supported
Counterhand is free for every store, with no paid tier and no locked features. Development and support are funded by GitHub Sponsors. The source is on GitHub — issues and pull requests are welcome.
Privacy
The plugin contacts no server of its own, collects no usage data and phones no telemetry home. It makes no outbound request until you ask it to — see the "External services" section below for exactly which services can be contacted, what is sent and when. Nothing is sent to the author of this plugin, ever.
https://yourstore.com/mcp) into Claude, ChatGPT, Claude Code, Cursor or VS Code — or use the one-click install buttons.Yes. Every tool, the chat, OAuth and the action log are in the one free plugin, licensed GPLv2 or later. There is no Pro version and nothing is unlocked by paying. If it saves you time, you can support its maintenance through GitHub Sponsors.
Add the endpoint URL (https://yourstore.com/mcp) to your MCP client — no token needed. The client discovers the OAuth authorization server, opens your browser to a consent screen, and you approve which scopes it may use. Approved assistants appear on the Connections tab.
Two causes: (1) pretty permalinks — the endpoint is also available at /wp-json/counterhand/v1/mcp, and re-saving Settings → Permalinks refreshes rewrite rules; (2) some servers block /.well-known/ paths. OAuth discovery lives at /.well-known/oauth-protected-resource, so your server must allow that path. On nginx, add before any dotfile-deny rule:
location ^~ /.well-known/ { try_files $uri $uri/ /index.php?$args; }
Any MCP client implementing the current authorization spec (OAuth 2.1 + PKCE + Protected Resource Metadata, with CIMD client identity): Claude on web, mobile and desktop, ChatGPT, Claude Code, Cursor, VS Code, and others.
Those apps connect from the vendor's own servers, not from your browser, so your store has to be reachable from the public internet over HTTPS. A local development site works fine with Claude Code, Cursor and VS Code, which connect from your own machine. The Connect AI apps tab checks this for you and says which of the two situations you are in.
Three things have to agree before a tool is callable: the group is switched on in Settings, the connection was granted that scope on the consent screen, and WooCommerce's own permission check passes for the logged-in owner of the connection. If any one of them says no, the tool is invisible and uncallable — it is never merely hidden. Check the Settings tab first, then the connection's scopes on the Connections tab.
The things that could are gated separately. Store settings, payment gateways and system maintenance are their own groups, off by default, sitting behind a collapsed Advanced heading that is never pre-ticked; each of their write tools requires an explicit confirmation; and the maintenance routines that cannot be undone are refused whatever an assistant sends. Calls to those three groups are recorded in the action log even if you have logging switched off.
The security model is OAuth-first. If you need a raw bearer token for a script or CI job, use the counterhand_rate_limit and related filters documented in the plugin, or open an issue on GitHub — a developer token path may be added.
Bugs and feature requests: the GitHub issue tracker or the support forum here. Security issues: please report them privately as described in the repository's SECURITY.md rather than in a public thread.