Connect
How the WooCommerce plugin and Shopify app set a shop up in one click, without the merchant copying a key. It is OAuth 2's authorization code flow with PKCE (S256). Only the getAddress() plugins can use it: the redirect each may name is fixed.
1. Send the merchant to getaddress.io
The plugin keeps a random state and a random code_verifier (43–128 characters), then opens:
https://getaddress.io/connect?client=woocommerce&shop=shop.example.com&redirect_uri=https%3A%2F%2Fshop.example.com%2Fwp-admin%2Fadmin.php%3Fpage%3Dwc-settings%26tab%3Dgetaddress&state=…&code_challenge=BASE64URL(SHA256(code_verifier))&code_challenge_method=S256
The merchant signs in or signs up and is asked once whether to connect the shop to their default subscription. Connect returns them to redirect_uri with code and state; Cancel with error=access_denied and state. The plugin checks state is the one it kept.
2. Exchange the code, from the shop's server
Request
POST https://api.getaddress.io/connect/token
{
"grant_type": "authorization_code",
"code": "Hk3…",
"code_verifier": "x9F…",
"client": "woocommerce",
"redirect_uri": "https://shop.example.com/wp-admin/admin.php?page=wc-settings&tab=getaddress"
}
Response
{
"api_key": "…",
"domain_token": "dtoken_…",
"subscription": "main",
"shop": "shop.example.com"
}
api_key is a key of the shop's own on the subscription: its look-ups count against the subscription like your API key's, and it can be revoked without touching yours. domain_token (WooCommerce only) is a domain token for the shop's domain made from it. A code works once, for ten minutes; anything else answers 400 invalid_grant.
3. Disconnect
POST https://api.getaddress.io/connect/revoke?api-key=the shop's key
Revokes the shop's key and every domain token made from it. Only a connection's own key is accepted (403 otherwise). You can also disconnect a shop under Connected shops in your console.