WooCommerce MCP

The Woo MCP tab (under AI Assistant → Woo MCP in the left sidebar) lets you connect a desktop AI client through WooCommerce’s own native MCP integration instead of the Connection URL. When connected this way, the AI gets access to WooCommerce’s core tools (orders, products, customers) plus all the AST PRO tracking tools — in a single connection.

A WooCommerce API key opens your whole store — orders, products, and customers — because the key belongs to WooCommerce and its scope cannot be narrowed. Treat it like a server password. Store it securely, never share it, and delete it in WooCommerce if it is exposed. If you only need tracking access, use the Connection URL route instead — it is scoped to tracking tools only.

Requires WooCommerce 10.9 or newer with the MCP integration feature switched on. To enable it, go to WooCommerce → Settings → Advanced → MCP and turn on Enable WooCommerce MCP.

AST PRO Woo MCP settings screen showing the API key fields, Copy config button, and Who is connected table

Set up the connection key

The WooCommerce MCP route authenticates using a WooCommerce REST API key.

  1. 1Click Create a key in WooCommerce to open the API key screen (or go to WooCommerce → Settings → Advanced → REST API).
  2. 2Give the key a name, select a user, and set Permissions. Read/Write is required for add and delete tracking. Read only is sufficient if you only need to look up tracking — choose the minimum permission you need.
  3. 3Click Generate API key. Copy both the Consumer Key (ck_…) and Consumer Secret (cs_…) immediately — the secret is shown only once.
  4. 4Back on the Woo MCP settings screen, paste the Consumer Key into the ck_ field and the Consumer Secret into the cs_ field, then click Use this key.

Connecting AI clients

    Who is connected

    The Who is connected table lists every AI client currently using this key. Each row shows Acting as, App, Connected, Last used, and Status. Because a WooCommerce key belongs to one account, every connection acts as that same account.

    Individual connections cannot be revoked one at a time — each holds the same key and would simply open a new session on the next request. Use Delete this key to end all access at once. A new key must be created and saved to reconnect.

    Forget key vs Delete this key

    ActionWhat it does
    Forget keyRemoves the key from AST PRO’s settings so the setup steps are hidden. The key itself continues to work in WooCommerce — it is not deleted and can still be used to make API calls. Use this to clean up the UI after switching to a different key.
    Delete this keyEnds all active connections using this key immediately. No AI client using this key can make further requests. You must create and save a new key to reconnect.

    About this key

    • Acting as — the WooCommerce account the key belongs to.
    • Named — the key’s description as set in WooCommerce.
    • Access — the key’s permission level (Read only or Read and write).
    • Last used — how long ago this key last made a request.

    What this key can do

    Everything accessible through WooCommerce MCP — WooCommerce’s own tools, plus the AST PRO tracking tools:

    ToolTypeDescription
    woocommerce-orders-getReadGet a single order by ID
    woocommerce-orders-listReadList orders with filters
    woocommerce-orders-createWriteCreate a new order
    woocommerce-orders-updateWriteUpdate an order
    woocommerce-products-getReadGet a single product
    woocommerce-products-listReadList products with filters
    woocommerce-products-createWriteCreate a new product
    woocommerce-products-updateWriteUpdate a product
    woocommerce-products-deleteDeleteDelete a product
    ast-pro-get-trackingReadRead tracking on an order
    ast-pro-get-orders-missing-trackingReadList unfulfilled orders with no tracking
    ast-pro-get-shipmentsReadList and count orders that have tracking
    ast-pro-add-trackingWriteAdd tracking to an order
    ast-pro-delete-trackingDeleteRemove a tracking entry from an order

    Troubleshooting

    • Key rejected / 401 error — confirm you pasted the Consumer Key in the ck_ field and the Consumer Secret in the cs_ field, not swapped. Both fields must be filled before clicking Use this key.
    • Tools absent after restarting Claude Desktop — open the config file and confirm the block was pasted inside the mcpServers object (not outside it). Restart Claude Desktop again after correcting it.
    • WooCommerce MCP feature not available — requires WooCommerce 10.9 or newer. Update WooCommerce, then go to WooCommerce → Settings → Advanced → MCP to enable the feature.