The AI features are off by default. To switch them on you provide your own API key for one of three providers. You are billed by that provider directly — there is no Zorem-hosted AI service and no additional charge from us.
Go to WooCommerce → Settings → Sales by Country.
This is the plugin’s only settings screen. The report itself at Analytics → Sales by Country needs no configuration.
manage_woocommerce capability — an Administrator or Shop manager — to see this tab, save a key or test a connection. If the tab is missing and you are on 1.6.8 or later, that is the reason.Setup steps
- Go to WooCommerce → Settings → Sales by Country.
- Tick Enable AI Insights.
- Choose your AI provider — Claude, ChatGPT or Gemini. Only the selected provider’s fields are shown.
- Paste your API key for that provider (see the table below for where to get one).
- Optionally set a model. Leave it blank to use the provider’s default.
- Click Test connection to confirm the key works.
- Click Save changes.
Providers and where to get a key
| Provider | Get an API key | Default model |
|---|---|---|
| Claude (Anthropic) | console.anthropic.com/settings/keys | claude-sonnet-5 |
| ChatGPT (OpenAI) | platform.openai.com/api-keys | gpt-4o-mini |
| Gemini (Google) | aistudio.google.com/app/apikey | gemini-2.5-flash |
Choosing a model
The Model field is free text, so you can use any model name your provider offers — including one released after this plugin version. Leave it blank and the provider’s default is used.
The models offered as suggestions are:
| Provider | Suggested models |
|---|---|
| Claude (Anthropic) | claude-opus-5, claude-sonnet-5, claude-haiku-4-5 |
| ChatGPT (OpenAI) | gpt-4o, gpt-4o-mini, gpt-4.1, gpt-4.1-mini |
| Gemini (Google) | gemini-2.0-flash, gemini-2.5-flash, gemini-2.5-pro |
Smaller, faster models (such as GPT-4o mini, Claude Haiku or Gemini Flash) are a good fit here: the plugin sends a small summary rather than large documents, so the cheaper models generally produce good results at a fraction of the cost.
Testing the connection
Test connection sends one very short prompt to the selected provider and reports whether it was accepted. It costs a fraction of a cent. It confirms three things at once: the key is valid, the model name is recognised, and your server can reach the provider.
| Message | What it means | What to do |
|---|---|---|
| Connection OK. | The key and model work. | Nothing — you are ready to use the AI panels. |
| Enter an API key first. | No key is saved for the selected provider. | Paste a key into the field, then test again. |
| An authentication or permission error | The key is wrong, revoked, or the account has no credit or quota left. | Re-copy the key from your provider’s dashboard and check the account has billing set up. |
| A model error | The model name is not recognised by that provider, or your account cannot access it. | Clear the Model field to fall back to the default. |
| The provider rejected the request. | The provider responded, but refused the call without a specific reason. | Check your account status with the provider; a suspended or over-quota account often looks like this. |
| A cURL or connection error, or a timeout | Your server could not reach the provider at all. This is the most common failure on managed hosting. | See the next section. |
If your server cannot reach the provider
The plugin calls the provider with WordPress’s own HTTP client, and waits up to 45 seconds. If that call cannot complete, the test shows the underlying connection error rather than a message from the provider. Common causes:
- Outbound HTTP is blocked by the host. Some managed WordPress hosts deny outbound connections by default and maintain an allowlist. Ask your host to permit
api.anthropic.com,api.openai.comorgenerativelanguage.googleapis.com, depending on your provider. WP_HTTP_BLOCK_EXTERNALis set inwp-config.php. If it is, add your provider’s host toWP_ACCESSIBLE_HOSTS.- A security plugin or firewall is intercepting outbound requests. Temporarily disable it to confirm, then allowlist the provider host.
- The request timed out. An overloaded server or a slow network path can exceed the 45-second limit. Retry; if it persists, try a faster model.
How your key is stored
Your API key is encrypted before it is written to the database, using a secret derived from your site’s own WordPress salts. After saving, the key is never sent back to your browser — the settings screen shows only a masked hint such as AIzaSy••••••••••TaXk so you can confirm which key is in place. It is never sent to Zorem.
Nothing about the request is logged. Your key, the data sent and the answers returned never appear in debug.log or under WooCommerce → Status → Logs.
To replace a key, paste the new one over the field and save. To remove one entirely, tick Remove the saved key and save.
AUTH salt in wp-config.php. Rotating salts — which some security plugins do, and which happens if salts are regenerated during a migration — makes the stored key impossible to decrypt. It is not lost from your provider, but this site can no longer read it, so paste it in again and save.