{"id":312719,"date":"2026-06-17T16:50:22","date_gmt":"2026-06-17T16:50:22","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/agentic-commerce-ai-readiness-toolkit\/"},"modified":"2026-08-27T08:03:41","modified_gmt":"2026-08-27T08:03:41","slug":"sdx-ai-readiness-toolkit","status":"publish","type":"plugin","link":"https:\/\/pt.wordpress.org\/plugins\/sdx-ai-readiness-toolkit\/","author":23356298,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.4.0","stable_tag":"0.4.0","tested":"7.1","requires":"7.0","requires_php":"7.4","requires_plugins":null,"header_name":"SDX AI Readiness Toolkit for WooCommerce","header_author":"Suhan Duman","header_description":"UCP, MCP, and ACP protocol support for WooCommerce with AI-readiness audit dashboard.","assets_banners_color":"5459d1","last_updated":"2026-08-27 08:03:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":172,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.3.0":{"tag":"0.3.0","author":"suhanduman","date":"2026-06-17 16:49:55","revision":3576151},"0.4.0":{"tag":"0.4.0","author":"suhanduman","date":"2026-08-27 08:03:41","revision":3668306}},"upgrade_notice":{"0.4.0":"<p>The \/.well-known\/ucp document now follows the UCP 2026-08-25 business profile schema; any integration that read the old <code>ucp_version<\/code> \/ <code>protocols<\/code> \/ <code>oauth<\/code> fields must switch to the <code>ucp<\/code> object and the new OAuth metadata endpoints. Visit the dashboard once after updating so the new .well-known routes are registered.<\/p>","0.3.0":"<p>WordPress 7.0 is now required. Security hardening, native WP 7.0 MCP integration, and selectable MCP\/ACP exposure modes.<\/p>","0.2.0":"<p>Major new ACP checkout module. Backwards compatible.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3576151,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3576151,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3576151,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3576151,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.3.0","0.4.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[267600,2353,242115,254710,286],"plugin_category":[45],"plugin_contributors":[247430],"plugin_business_model":[],"class_list":["post-312719","plugin","type-plugin","status-publish","hentry","plugin_tags-acp","plugin_tags-ai","plugin_tags-mcp","plugin_tags-ucp","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-suhanduman","plugin_committers-suhanduman"],"banners":{"banner":"https:\/\/ps.w.org\/sdx-ai-readiness-toolkit\/assets\/banner-772x250.png?rev=3576151","banner_2x":"https:\/\/ps.w.org\/sdx-ai-readiness-toolkit\/assets\/banner-1544x500.png?rev=3576151","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sdx-ai-readiness-toolkit\/assets\/icon-128x128.png?rev=3576151","icon_2x":"https:\/\/ps.w.org\/sdx-ai-readiness-toolkit\/assets\/icon-256x256.png?rev=3576151","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>SDX AI Readiness Toolkit<\/strong> makes any WooCommerce store auto-discoverable, readable, and purchasable by AI shopping agents \u2014 ChatGPT plugins, Perplexity Shopping, Google's commerce AI, custom Claude tools, and any agent that speaks the open protocols of the agentic commerce ecosystem.<\/p>\n\n<h4>Why this matters<\/h4>\n\n<p>In 2026 Google launched the <strong>Universal Commerce Protocol (UCP)<\/strong> with Shopify, Walmart, Target, Wayfair, and Etsy. WooCommerce was absent. This plugin closes that gap.<\/p>\n\n<h4>What this plugin does<\/h4>\n\n<ul>\n<li><strong>UCP business profile<\/strong> at <code>\/.well-known\/ucp<\/code> \u2014 a spec-conformant UCP 2026-08-25 profile agents can negotiate against<\/li>\n<li><strong>UCP shopping catalog<\/strong> at <code>\/wp-json\/agtc\/v1\/ucp\/catalog\/\u2026<\/code> \u2014 the <code>dev.ucp.shopping.catalog.search<\/code> and <code>.lookup<\/code> capabilities, served from your own products<\/li>\n<li><strong>MCP server<\/strong> at <code>\/wp-json\/agtc\/v1\/mcp<\/code> \u2014 JWT-authenticated tools for product listing, search, and order lookup, speaking every MCP revision from 2024-11-05 to 2026-07-28<\/li>\n<li><strong>ACP checkout<\/strong> at <code>\/wp-json\/agtc\/v1\/acp\/checkouts<\/code> \u2014 agentic checkout sessions with Stripe <code>payment_intent<\/code> support<\/li>\n<li><strong>OAuth 2.0 server with discovery<\/strong> \u2014 dynamic client registration, <code>client_credentials<\/code> grant, and RFC 8414 \/ RFC 9728 metadata so MCP clients configure themselves<\/li>\n<li><strong>Coexistence with WooCommerce core<\/strong> \u2014 defers to WooCommerce's native ACP checkout and to its canonical product\/order Abilities instead of duplicating them<\/li>\n<li><strong>Web discovery<\/strong> \u2014 HTML <code>&lt;link&gt;<\/code> tags, HTTP Link headers, <code>robots.txt<\/code> advisory, <code>\/llms.txt<\/code><\/li>\n<li><strong>Google Merchant Center feed<\/strong> at <code>\/merchant-feed\/google.xml<\/code> \u2014 a self-hosted, Google-spec product feed you register as a scheduled fetch<\/li>\n<li><strong>AI readiness dashboard<\/strong> \u2014 scores your store, shows what's missing, offers one-click fixes<\/li>\n<li><strong>Production-grade engineering<\/strong> \u2014 396 unit tests, integration-tested on live WordPress + WooCommerce, WordPress Coding Standards compliant, PHP 7.4+ compatible<\/li>\n<\/ul>\n\n<h4>How agents use your store<\/h4>\n\n<ol>\n<li>Agent fetches <code>\/.well-known\/ucp<\/code> and negotiates the capabilities you publish<\/li>\n<li>Agent searches your catalog at <code>\/ucp\/catalog\/search<\/code> (UCP) \u2014 no credentials needed for public product data<\/li>\n<li>Agent discovers how to authenticate at <code>\/.well-known\/oauth-authorization-server<\/code><\/li>\n<li>Agent registers via <code>\/oauth\/register<\/code> \u2192 receives client ID + secret<\/li>\n<li>Agent exchanges credentials for JWT at <code>\/oauth\/token<\/code><\/li>\n<li>Agent calls MCP tools under <code>\/mcp<\/code> (search, list, order lookup)<\/li>\n<li>Agent creates an ACP checkout session at <code>\/acp\/checkouts<\/code><\/li>\n<li>Agent completes the session \u2192 real WooCommerce order in your admin<\/li>\n<\/ol>\n\n<p>All standard payment gateways work. UCP creates standard WC orders.<\/p>\n\n<h4>How this actually helps your store<\/h4>\n\n<p>AI shopping assistants \u2014 ChatGPT, Perplexity, Gemini, Claude \u2014 now help millions of people find products every day. When a shopper asks \"find me a waterproof backpack under $80\", the assistant increasingly queries machine-readable storefronts instead of crawling pages. A UCP platform starts by fetching <code>\/.well-known\/ucp<\/code> on the domains it knows, reads which capabilities the store supports, and calls those endpoints. A store with no profile \u2014 or with a profile the platform cannot parse \u2014 simply is not part of that conversation.<\/p>\n\n<p>This plugin publishes a conformant profile automatically, serves the UCP catalog capabilities behind it, and exposes the same catalog through MCP. You don't have to write a single line of integration code; activating the plugin is enough to put your store on the map for agents that speak UCP, MCP, or ACP.<\/p>\n\n<p>A few complementary moves we recommend alongside this plugin: register your products in <strong>Google Merchant Center<\/strong> so the Google Shopping feed picks them up, keep product titles and descriptions clear and well-structured (the same SEO discipline that helps humans also helps AI parsing), and make sure your site runs on HTTPS end-to-end so agents trust the responses.<\/p>\n\n<p>Once your store is published, agents can do three things that previously required a human: discover that you exist, browse your catalog in real time, and \u2014 with ACP enabled \u2014 create a real WooCommerce order on behalf of their user, with the same checkout, tax, shipping, and fulfillment plumbing your human customers go through today.<\/p>\n\n<p>A note on where the money moves: ChatGPT's Instant Checkout was retired in March 2026, and the buyer now completes payment on the merchant's own checkout. That is exactly the \"Model B\" flow described in the FAQ below, and it works with whatever gateway your store already uses \u2014 so the practical path for most stores is discovery and catalog access first, agent-initiated orders second.<\/p>\n\n<h4>Google Merchant Center<\/h4>\n\n<p>The plugin publishes a Google-spec product feed at <code>https:\/\/yourstore.com\/merchant-feed\/google.xml<\/code>. It is fully self-hosted \u2014 the plugin contacts no external service. Instead, you register that URL in <strong>Google Merchant Center \u2192 Products \u2192 Feeds<\/strong> as a scheduled fetch, and Google pulls the feed on its own schedule. Once Google has the feed, your products become eligible for Google Shopping and Google's shopping AI.<\/p>\n\n<p>The feed is built from your published, catalog-visible WooCommerce products and includes each product's title, description, price, availability, image, and \u2014 when set \u2014 brand and GTIN. Filling in <strong>brand<\/strong> and <strong>GTIN<\/strong> (Products \u2192 product \u2192 Inventory \u2192 Global Unique ID, on WooCommerce 9.2+) materially improves listing quality and how often Google can match your products. Variable products are expanded to their purchasable variations. The generated XML is cached for one hour to keep the endpoint fast.<\/p>\n\n<h4>Privacy &amp; Data Handling<\/h4>\n\n<p>This plugin is built to be conservative about data:<\/p>\n\n<ul>\n<li>The plugin only exposes publicly available product data \u2014 name, price, image, description \u2014 through its UCP and MCP discovery endpoints. Anything you already display on a public product page is fair game; nothing else is.<\/li>\n<li>Order data is gated behind a valid OAuth 2.0 access token AND is scoped to the agent's own orders. An agent (OAuth client) can only read orders it created itself through the ACP checkout flow; it can never read other agents' orders or orders placed by human customers through normal checkout. An agent without the <code>read:orders<\/code> scope cannot read any orders at all, and <code>read:orders<\/code> is never granted by open client registration unless it is explicitly requested.<\/li>\n<li>No customer personally identifiable information (PII) is collected, transmitted to third parties, or stored beyond standard WooCommerce order records that WooCommerce itself already manages.<\/li>\n<li>All admin actions \u2014 including the audit dashboard and one-click auto-fix buttons \u2014 require the <code>manage_woocommerce<\/code> capability and a verified WordPress CSRF nonce.<\/li>\n<li>No outbound telemetry. No analytics calls. No external \"phone home\" requests. The plugin does not contact the author, an analytics vendor, or any third party at install time, on activation, or during normal operation.<\/li>\n<\/ul>\n\n<h4>External Services<\/h4>\n\n<p>WordPress.org guideline #6 requires that we disclose any external services this plugin contacts. The list is short:<\/p>\n\n<ul>\n<li><strong>Stripe (optional, opt-in):<\/strong> Stripe is only contacted when the ACP module's <code>payment_intent<\/code> flow is explicitly enabled by defining the <code>AGTC_STRIPE_SECRET_KEY<\/code> constant in <code>wp-config.php<\/code>. When an agent completes a checkout session under that flow, the plugin makes a server-to-server POST to <code>https:\/\/api.stripe.com\/v1\/payment_intents<\/code> to authorize the payment. No data is sent to Stripe unless this flow is activated. Stripe service terms: https:\/\/stripe.com\/legal \u2014 Stripe privacy policy: https:\/\/stripe.com\/privacy.<\/li>\n<li><strong>No other external services are contacted by default.<\/strong> UCP, MCP, and ACP discovery endpoints are served from your own WordPress installation. The agent pulls data <em>from<\/em> you; you do not push data <em>to<\/em> the agent or to any intermediary.<\/li>\n<\/ul>\n\n<h4>Disclaimer<\/h4>\n\n<p>This plugin is an independent, community-driven implementation of open commerce protocols. It is not affiliated with, endorsed by, or sponsored by Stripe, Inc., OpenAI, Google, Anthropic, Automattic, or the WooCommerce trademark holders. \"WooCommerce\" is a trademark of Automattic Inc. and is referenced solely for descriptive interoperability purposes.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload to <code>\/wp-content\/plugins\/agtc-commerce<\/code> (or install via WP admin \u2192 Plugins \u2192 Add New)<\/li>\n<li>Activate via Plugins menu<\/li>\n<li>Visit <strong>SDX AI Readiness<\/strong> in the admin sidebar to see the AI Readiness dashboard<\/li>\n<li>(Optional) Define <code>AGTC_STRIPE_SECRET_KEY<\/code> in <code>wp-config.php<\/code> to enable ACP payment intents<\/li>\n<\/ol>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 7.0 or higher (tested on 7.1)<\/li>\n<li>WooCommerce 8.0 or higher (tested on 11.0)<\/li>\n<li>PHP 7.4 or higher (PHP 8.x recommended)<\/li>\n<li>OpenSSL and libsodium PHP extensions<\/li>\n<li>Pretty Permalinks enabled<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20conflict%20with%20woocommerce%27s%20built-in%20acp%20support%3F\"><h3>Will this conflict with WooCommerce's built-in ACP support?<\/h3><\/dt>\n<dd><p>No. WooCommerce 10.7+ ships internal ACP infrastructure with the <code>agentic_checkout<\/code> feature flag (default off). Our <code>Coexistence<\/code> detector activates our endpoints only when the WC native flag is off, and defers (410 + Location header) when on.<\/p><\/dd>\n<dt id=\"will%20this%20duplicate%20woocommerce%27s%20own%20mcp%20tools%3F\"><h3>Will this duplicate WooCommerce's own MCP tools?<\/h3><\/dt>\n<dd><p>No. WooCommerce 10.9+ registers seven canonical abilities of its own (<code>woocommerce\/products-query<\/code>, <code>orders-query<\/code> and friends) through the WordPress MCP Adapter. Two near-identical tool sets in front of the same agent makes tool selection worse, so the \"WP Abilities\" setting defaults to <code>auto<\/code>: when WooCommerce's canonical abilities are present, this plugin does not register its overlapping set, and the dashboard's MCP-004 check tells you that happened. Set the mode to <code>all<\/code> (or filter <code>agtc_mcp_abilities_mode<\/code>) if you want both. The plugin's own OAuth MCP server at <code>\/wp-json\/agtc\/v1\/mcp<\/code> is unaffected either way.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20work%20on%20wordpress%207.1%3F\"><h3>Does the plugin work on WordPress 7.1?<\/h3><\/dt>\n<dd><p>Yes \u2014 the release is integration-tested against a live WordPress 7.1 + WooCommerce 11.0.1 install: the UCP profile, the catalog capabilities, the MCP server, OAuth registration and token exchange, the ACP purchase flow that creates a real order, and the readiness dashboard all pass there. WordPress 7.1 keeps PHP 7.4 as its minimum, so no PHP change is needed.<\/p><\/dd>\n<dt id=\"which%20ucp%20version%20does%20the%20profile%20publish%3F\"><h3>Which UCP version does the profile publish?<\/h3><\/dt>\n<dd><p>UCP 2026-08-25, date-versioned as the specification requires. The profile advertises only the capabilities this plugin actually serves \u2014 currently <code>dev.ucp.shopping.catalog.search<\/code> and <code>dev.ucp.shopping.catalog.lookup<\/code> \u2014 because a platform negotiates against that document, and an over-claimed capability fails later in a worse place. <code>payment_handlers<\/code> is published as an empty map until the UCP checkout capability ships. You can extend the document with the <code>agtc_ucp_profile<\/code> filter.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20uninstall%3F\"><h3>What happens to my data if I uninstall?<\/h3><\/dt>\n<dd><p>Nothing is deleted by default. Deactivating the plugin only withdraws its rewrite rules; your signing keys, registered OAuth clients and settings stay put, so reactivating restores the exact same store identity. Deleting the plugin also leaves that data alone unless you tick <strong>Delete all plugin data on uninstall<\/strong> on the dashboard first \u2014 that opt-in exists because the master secret encrypts stored client data, and removing it cannot be undone.<\/p><\/dd>\n<dt id=\"is%20the%20public%20catalog%20endpoint%20rate%20limited%3F\"><h3>Is the public catalog endpoint rate limited?<\/h3><\/dt>\n<dd><p>Yes: 60 requests per minute, counted per declared platform profile (falling back to the caller's IP address). Over the limit the endpoint answers <code>429<\/code> with a <code>Retry-After<\/code> header and a UCP <code>rate_limited<\/code> message, which platforms are expected to honour. Tune or disable it with the <code>agtc_ucp_catalog_rate_limit<\/code> filter \u2014 returning <code>0<\/code> turns throttling off.<\/p><\/dd>\n<dt id=\"do%20agents%20need%20credentials%20to%20search%20the%20catalog%3F\"><h3>Do agents need credentials to search the catalog?<\/h3><\/dt>\n<dd><p>No. The UCP catalog endpoints expose only data your storefront already shows publicly, so they are unauthenticated. They do require the <code>UCP-Agent<\/code> header the specification mandates, so a misconfigured caller gets a protocol-shaped error rather than silently reading your catalog; the <code>agtc_ucp_require_agent_header<\/code> filter can relax that. Order data always requires an OAuth token and is scoped to the agent's own orders.<\/p><\/dd>\n<dt id=\"do%20i%20need%20stripe%3F\"><h3>Do I need Stripe?<\/h3><\/dt>\n<dd><p>Only for ACP payment_intent flow. Without Stripe, agents can still discover, browse, and create checkout sessions \u2014 they just can't authorize payment through ACP directly.<\/p>\n\n<p>There are two flow models to choose from, and most stores can start without Stripe entirely:<\/p>\n\n<ul>\n<li><strong>Model A \u2014 Agent pays directly (ACP <code>payment_intent<\/code>):<\/strong> Requires Stripe. The ACP protocol uses Stripe's PaymentIntent under the hood, so you must define <code>AGTC_STRIPE_SECRET_KEY<\/code> in <code>wp-config.php<\/code>. The agent never sees the customer's card; payment is captured server-side at session completion. This is the fully autonomous flow.<\/li>\n<li><strong>Model B \u2014 Agent creates order, customer pays later:<\/strong> Works with <strong>any<\/strong> WooCommerce payment gateway \u2014 PayPal, Square, Stripe via WooCommerce Payments, bank transfer, cash on delivery, anything you already have configured. The agent creates an ACP session, which the plugin converts into a standard pending WooCommerce order. The customer receives an order link and completes payment using whatever gateway your store already uses.<\/li>\n<li><strong>Recommendation:<\/strong> Most stores should start with Model B (no Stripe required) and add Model A later if and when they want fully autonomous agent purchases without a human checkout step.<\/li>\n<\/ul><\/dd>\n<dt id=\"what%20data%20does%20this%20expose%20to%20agents%3F\"><h3>What data does this expose to agents?<\/h3><\/dt>\n<dd><p>By default, public product data only (name, price, description, images). An agent can additionally read its <strong>own<\/strong> orders if it holds the <code>read:orders<\/code> scope \u2014 but only orders it created itself through the ACP checkout flow. Agents never see other agents' orders or orders placed by human customers through normal checkout.<\/p><\/dd>\n<dt id=\"how%20do%20i%20let%20agents%20read%20orders%3F\"><h3>How do I let agents read orders?<\/h3><\/dt>\n<dd><p>Order access is scoped to ownership and safe by default: an agent (OAuth client) can only ever read orders it created itself via the ACP checkout flow. It can never read another agent's orders or orders placed by human customers through normal checkout.<\/p>\n\n<p>To read its own orders, an agent must request the <code>read:orders<\/code> scope at registration; dynamic client registration only ever grants <code>read:products<\/code> by default, so <code>read:orders<\/code> must always be requested explicitly. No server-side opt-in or <code>wp-config.php<\/code> constant is required.<\/p><\/dd>\n<dt id=\"is%20the%20oauth%20flow%20secure%3F\"><h3>Is the OAuth flow secure?<\/h3><\/dt>\n<dd><p>Yes. Client secrets are hashed with <code>password_hash()<\/code>. Access tokens are RS256-signed JWTs with <code>iat<\/code>, <code>exp<\/code> (max 2h), <code>aud<\/code>, <code>iss<\/code>, and <code>jti<\/code> claims. Admin endpoints require WP nonce + <code>manage_woocommerce<\/code>.<\/p><\/dd>\n<dt id=\"how%20do%20i%20rotate%20the%20jwks%20keypair%3F\"><h3>How do I rotate the JWKS keypair?<\/h3><\/dt>\n<dd><p>Open the AI Readiness dashboard. If JWKS rotation is needed, click the \"Rotate JWKS keypair now\" button. Old key remains valid for a 24h grace period.<\/p><\/dd>\n<dt id=\"wordpress%20abilities%20and%20the%20mcp%20adapter\"><h3>WordPress Abilities and the MCP Adapter<\/h3><\/dt>\n<dd><p>WordPress core ships the Abilities API (since 6.9) and the PHP AI Client (7.0). The <strong>MCP Adapter is not part of WordPress core<\/strong> \u2014 it is maintained separately by the WordPress AI team, and WooCommerce 11.0 already bundles it as a library, so most stores do not need to install anything. It stays dormant until you enable WooCommerce's <code>mcp_integration<\/code> feature (WooCommerce \u2192 Settings \u2192 Advanced \u2192 Features); after that, MCP clients such as Claude Desktop, Claude Code, Cursor or VS Code can reach WordPress abilities using ordinary application passwords. The dashboard's MCP-004 check tells you which of these two states you are in.<\/p>\n\n<p>This plugin registers its tools as Abilities so they are available through that adapter, using the unified <code>meta.public<\/code> exposure flag introduced in WordPress 7.1 (the older per-channel flags are kept for adapters that predate it). Its own OAuth MCP server stays active alongside the adapter and continues to serve headless or autonomous agents that manage their own credentials.<\/p>\n\n<p>The AI Readiness dashboard shows a \"Protocol exposure\" card with four settings:<\/p>\n\n<p>MCP exposure controls which MCP path is active: \"both\" (default \u2014 the adapter and the plugin server run side by side), \"core\" (plugin's own MCP server is disabled, traffic goes to the adapter only), or \"plugin\" (adapter integration is disabled, plugin MCP server only).<\/p>\n\n<p>WP Abilities controls what happens when WooCommerce registers its own canonical abilities: \"auto\" (default \u2014 this plugin stands down so agents do not see two overlapping tool sets) or \"all\" (register both).<\/p>\n\n<p>ACP exposure controls ACP checkout availability: \"auto\" (default \u2014 plugin ACP is active when WooCommerce native ACP is off, deferred when on), \"plugin\" (plugin ACP is always active regardless of WC native state), or \"off\" (ACP checkout is fully disabled).<\/p>\n\n<p>UCP exposure turns the UCP profile's advertised services and the catalog endpoints \"on\" (default) or \"off\".<\/p>\n\n<p>All four can be overridden programmatically with the filters agtc_mcp_exposure_mode, agtc_mcp_abilities_mode, agtc_acp_exposure_mode and agtc_ucp_exposure_mode, which receive the stored option value and should return one of the accepted mode strings.<\/p><\/dd>\n<dt id=\"how%20do%20i%20get%20my%20products%20into%20google%20shopping%3F\"><h3>How do I get my products into Google Shopping?<\/h3><\/dt>\n<dd><p>The plugin publishes a Google-spec product feed at <code>https:\/\/yourstore.com\/merchant-feed\/google.xml<\/code>. In Google Merchant Center, go to <strong>Products \u2192 Feeds<\/strong>, add a new feed, and choose the <strong>scheduled fetch<\/strong> option pointing at that URL. Google then fetches the feed on its own schedule \u2014 the plugin never contacts Google. The feed carries title, description, price, availability, image, and brand\/GTIN when set; adding a brand and GTIN to each product improves listing quality and match rate. The dashboard's FEED-001 check flags products missing those attributes.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>New: UCP 2026-08-25 conformant business profile at <code>\/.well-known\/ucp<\/code> (<code>ucp<\/code> object, date version, services, capabilities, <code>keys<\/code> JWK set, required caching headers)<\/li>\n<li>New: UCP shopping catalog capabilities \u2014 <code>dev.ucp.shopping.catalog.search<\/code> and <code>.lookup<\/code> served at <code>\/wp-json\/agtc\/v1\/ucp\/catalog\/{search,lookup,product}<\/code><\/li>\n<li>New: MCP protocol negotiation across every revision from 2024-11-05 to 2026-07-28 (<code>initialize<\/code>, <code>server\/discover<\/code>, <code>_meta<\/code> version declaration)<\/li>\n<li>New: MCP tool results as spec-shaped content blocks, cacheable <code>tools\/list<\/code>, deterministic tool order<\/li>\n<li>New: OAuth metadata discovery \u2014 RFC 8414 authorization server metadata and RFC 9728 protected resource metadata, plus a <code>WWW-Authenticate<\/code> challenge on 401<\/li>\n<li>New: coexistence with WooCommerce 10.9+ canonical abilities via the \"WP Abilities\" exposure mode<\/li>\n<li>New: UCP exposure mode and the <code>agtc_ucp_profile<\/code> filter<\/li>\n<li>New: rate limiting on the public catalog endpoints (60\/min per platform, <code>agtc_ucp_catalog_rate_limit<\/code> filter)<\/li>\n<li>New: opt-in data removal on uninstall, plus automatic rewrite handling on activation and deactivation<\/li>\n<li>Changed: verified against a live WordPress 7.1 + WooCommerce 11.0.1 stack; 396 unit tests + 21 integration tests; CI covers PHP 7.4\u20138.5<\/li>\n<li>Changed: documentation corrected \u2014 the MCP Adapter is a canonical plugin, not part of WordPress core<\/li>\n<li>Removed: the old non-standard UCP profile shape (<code>ucp_version: \"1.0\"<\/code>, <code>protocols<\/code>, <code>oauth<\/code>, <code>jwks_uri<\/code>)<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Security: plugin-owned key derivation (MasterKey) replacing reuse of WordPress auth salts<\/li>\n<li>Security: AES-256-GCM at-rest encryption for sensitive stored data<\/li>\n<li>Security: MCP tool scope enforcement; order tools scoped to the agent's own orders<\/li>\n<li>New: Google Merchant Center product feed at <code>\/merchant-feed\/google.xml<\/code> + dashboard feed-readiness audit<\/li>\n<li>New: WordPress 7.0 native MCP integration \u2014 tools registered as Abilities for the core MCP Adapter<\/li>\n<li>New: selectable MCP exposure (both\/core\/plugin) and ACP exposure (auto\/plugin\/off) with dashboard controls and filters<\/li>\n<li>Changed: minimum WordPress raised to 7.0<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>New: ACP checkout module with Stripe payment_intent + WC native coexistence<\/li>\n<li>New: Outbound webhook dispatcher with Ed25519 signing<\/li>\n<li>New: Severity-grouped dashboard with remediation cards and one-click auto-fix buttons<\/li>\n<li>New: <code>\/admin\/fix<\/code> REST endpoint with nonce + capability check<\/li>\n<li>Fix: PHP 8.5 deprecation warnings (<code>setAccessible<\/code>, <code>curl_close<\/code>)<\/li>\n<li>Fix: JwtVerifier enforces <code>iat<\/code> claim and 2h max token lifetime<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: Core, MCP, UCP, Discovery hints<\/li>\n<\/ul>","raw_excerpt":"Make your WooCommerce store first-class compatible with AI shopping agents: UCP discovery, MCP tools, OAuth 2.0, ACP checkout, audit dashboard.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/312719","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=312719"}],"author":[{"embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/suhanduman"}],"wp:attachment":[{"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=312719"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=312719"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=312719"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=312719"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=312719"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pt.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=312719"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}