Loading...
Sign in to see the examples with your own API key.

Connect

How the WooCommerce plugin and Shopify app set a shop up in one click, without the merchant copying a key. It is OAuth 2's authorization code flow with PKCE (S256). Only the getAddress() plugins can use it: the redirect each may name is fixed.

1. Send the merchant to getaddress.io

The plugin keeps a random state and a random code_verifier (43–128 characters), then opens:

https://getaddress.io/connect?client=woocommerce&shop=shop.example.com&redirect_uri=https%3A%2F%2Fshop.example.com%2Fwp-admin%2Fadmin.php%3Fpage%3Dwc-settings%26tab%3Dgetaddress&state=…&code_challenge=BASE64URL(SHA256(code_verifier))&code_challenge_method=S256

The merchant signs in or signs up and is asked once whether to connect the shop to their default subscription. Connect returns them to redirect_uri with code and state; Cancel with error=access_denied and state. The plugin checks state is the one it kept.

2. Exchange the code, from the shop's server

Request

POST https://api.getaddress.io/connect/token
{
    "grant_type": "authorization_code",
    "code": "Hk3…",
    "code_verifier": "x9F…",
    "client": "woocommerce",
    "redirect_uri": "https://shop.example.com/wp-admin/admin.php?page=wc-settings&tab=getaddress"
}

Response

{
    "api_key": "…",
    "domain_token": "dtoken_…",
    "subscription": "main",
    "shop": "shop.example.com"
}

api_key is a key of the shop's own on the subscription: its look-ups count against the subscription like your API key's, and it can be revoked without touching yours. domain_token (WooCommerce only) is a domain token for the shop's domain made from it. A code works once, for ten minutes; anything else answers 400 invalid_grant.

3. Disconnect

POST https://api.getaddress.io/connect/revoke?api-key=the shop's key

Revokes the shop's key and every domain token made from it. Only a connection's own key is accepted (403 otherwise). You can also disconnect a shop under Connected shops in your console.

Top