Customer Info includes a built-in MCP server (Model Context Protocol) that lets Claude — or any MCP client — answer questions about your customers directly from your store. Instead of copying data into a chat window, you connect once by URL and ask questions in plain English.
It is read-only. There are no write tools — saving a customer, switching users and the settings endpoints are deliberately not exposed.
🔌 Is it on? Where do I turn it off?
manage_woocommerce, so nothing can read any data until you approve a connection. Unapproved and anonymous requests are rejected. To remove the endpoint entirely, deactivate the plugin.⚠️ Test on staging first
Approving a connection grants an AI client read access to personal customer data — names, full addresses and phone numbers (via get_customer_summary), order history, subscriptions and support conversations. Try it on a staging site first, and make sure the access fits your privacy policy.
search_customers plus the per-customer tools can walk your whole customer base a page at a time (each call returns up to 100 records). Treat an approved connection as handing that client the same read access to customer PII that a shop manager has.✅ Requirements
- WooCommerce active — the tools return an error without it.
- HTTPS — required by the OAuth spec and by Claude’s connector.
- Pretty permalinks — the authorize page and discovery documents need them.
- A WordPress account with the
manage_woocommercecapability (Shop manager or Administrator) to approve the connection.
🔗 Connecting Claude
Add this URL as a custom connector in Claude, replacing the domain with your own store:
https://your-store.com/wp-json/customer-info-mcp/v1/mcp
Claude handles the rest — it discovers the store’s authorization server, registers itself, sends you to a WordPress login and an Approve screen (PKCE required), and exchanges the result for an access token. Nothing is installed locally, and teammates connect the same way with their own accounts.
🧰 What Claude can ask for
| Tool | What it returns |
|---|---|
| search_customers | Finds accounts by partial email, name or username — the starting point for a vague identifier. |
| get_customer_summary | The full 360-degree profile: identity, full addresses, account age, lifetime value, order and subscription counts, support volume and wp-admin links. |
| get_customer_orders | Orders newest first, with line items, totals, refunds, status, coupons and payment method. |
| get_customer_subscriptions | Subscriptions with status, next renewal, recurring total, and licence activation limits when WooCommerce API Manager is active. |
| get_customer_clv | Revenue analysis: gross and net lifetime value, average order value, first and last order dates, and revenue per year. |
| get_support_history | Past Help Scout and Intercom conversations merged into one list, newest first — this surfaces third-party support content. |
Each list tool returns at most 100 records per call, so a large customer or order history is paged. In practice you just ask — who is this customer, where is their licence being used, are they at risk of churning — and Claude picks the right tools.
🔐 How access is secured
- Every token resolves to the real WordPress user who approved it, so every request is attributable to a person — unlike Switch to Customer, MCP calls carry an identity.
- Access requires the
manage_woocommercecapability, re-checked on every call. - Access tokens last 1 hour; refresh tokens last 30 days and rotate on every use, so a replayed token is rejected.
- Codes and tokens are stored hashed (sha256); the plaintext is shown only once.
- A daily cron prunes expired codes, tokens and abandoned client registrations.
🚫 Revoking access
| Connection type | How to cut it off |
|---|---|
| Application password (curl / local clients) | Delete it at Users → Profile → Application Passwords. Takes effect immediately. |
| OAuth connection (Claude and other agents) | There is no “connected apps” list in this version. To cut a client off at once, remove the approving user’s manage_woocommerce capability (or deactivate that user) — every call re-checks it. Otherwise access lapses when the refresh token expires (30 days) and the daily prune runs. |
| Everything at once | Deactivate the plugin — the endpoint and the OAuth server go away entirely. |
🧪 Other ways to connect
The endpoint also accepts standard WordPress authentication, so an application password over HTTP Basic works without OAuth — handy for a local client or a quick test. Create one at Users → Profile → Application Passwords; it is a revocable token, not your login password. A shared-secret dev bypass also exists for testing but is off by default and is never honoured when the site’s environment type is production; if it is ever left enabled, an admin notice warns you.
🧰 Troubleshooting
| Problem | What to check |
|---|---|
404 on the endpoint or the .well-known discovery URL | Pretty permalinks are off (Settings → Permalinks → Save), or a security plugin is blocking the REST API or the .well-known path. |
| The connector won’t register or discover the server | HTTPS is required. Confirm the site is served over HTTPS and reachable from outside — a staging site behind Basic Auth or an allow-list will block discovery. |
| Approve screen returns an auth error | The account you logged in with lacks manage_woocommerce. Approve with an Administrator or Shop manager account. |
| Calls worked, then stopped after a while | The access token expired (1 hour) and the client did not refresh, or the refresh token passed 30 days. Reconnect. |