Ecommerce
WooCommerce
Send orders to OrcLink by WooCommerce webhook. Each paid order becomes an order outcome, matched to the ad click by the olid the OrcLink plugin saves on the order.
Live: shipped in OrcLink's production release before this one. Built, not yet tested live: built and tested with sample data, not yet run against a live account of the vendor. Coming soon: listed, not available to connect yet.
How to connect
- Dashboard > Integrations > WooCommerce > Connect. Copy the webhook URL and the secret (shown once) into WooCommerce.
What OrcLink reads
- Orders, by WooCommerce webhook. Each paid order becomes an order outcome, matched to the ad click by the olid the OrcLink plugin saves on the order.
What OrcLink writes back
- The OrcLink plugin saves the click id (olid) on each order in your store.
Never stored
- Raw email addresses and phone numbers: hashed (SHA-256) the moment they arrive.
- The raw payload: only its SHA-256, for provenance.
- Your credentials and webhook secrets in clear: they are stored encrypted (AES-256-GCM).
Known limits
- Not yet installed on a real store.
UNTESTED on a real store. The adapter (app/lib/outcomes/sources/woocommerce.ts) is tested against a fixture built from the public WooCommerce REST v3 order shape.
1. Connect in OrcLink
Dashboard > Integrations > WooCommerce > Connect. Copy the webhook URL and the webhook secret. The secret is shown once. "New secret" makes a new one and the old one stops working.
2. Install the plugin
Zip the folder integrations/woocommerce/orclink/ (the zip root is orclink/) and upload it in WordPress > Plugins > Add New > Upload. Activate it. Then Settings > OrcLink: set the workspace id, your tag domain (the host that serves /t.js, for example t.yourdomain.com) and the OrcLink app URL.
The plugin:
- prints
<script async src="https://<tag domain>/t.js?w=<workspace id>" data-w="<workspace id>">in<head>; - copies the
orc_olidcookie (written by/t.jsafter advertising consent) into the order metaorclink_olidat checkout (classic and block checkout). With no valid cookie (no consent, consent withdrawn, expired) it deletes that meta, so a reused block-checkout draft order never keeps an older click id. Orders placed with no cookie have no olid and are recorded unattributed; - sets the order meta
orclink_test = 1whenwp_get_environment_type()is notproduction. OrcLink then records the order as a test order (never revenue).
The meta key has no leading underscore on purpose: WooCommerce hides _keys from webhook payloads.
Deleting the plugin (Plugins > Delete, not Deactivate) runs uninstall.php, which removes the plugin's three options. The orclink_olid / orclink_test meta stays on past orders as part of the order record.
3. Create two webhooks
WooCommerce > Settings > Advanced > Webhooks > Add webhook:
| Setting | Value |
|---|---|
| Topic | Order created, then a second webhook with Order updated |
| Delivery URL | the OrcLink webhook URL |
| Secret | the OrcLink webhook secret |
| API version | WP REST API Integration v3 |
A refund and a status change both arrive as Order updated. WooCommerce builds the payload when it delivers, so it is the order's current state. When you save a webhook, WooCommerce posts a ping (webhook_id=N) without a signature; OrcLink answers it 200 and ignores it (before it even looks up the workspace).
Deliveries are not retried. WooCommerce sends each event once, logs a failed delivery, and switches the webhook off (status Disabled) after more than 5 failed deliveries in a row. OrcLink never answers a signed delivery 429; it answers 500 only when it could not record the order (a database outage), and keeps no copy of the raw order to retry later (it holds personal data). Check the OrcLink Integrations card: it shows when the last order was received. If it stops moving, look at WooCommerce > Settings > Advanced > Webhooks and turn the webhook back on.
One store per connection. OrcLink binds the connection to the first store that delivers (the X-WC-Webhook-Source URL WooCommerce sends) and refuses orders from another store with the note "This connection is bound to <store>; connect the other store in its own workspace" (two stores share order numbers). The store is its host (lower case, without www., a path or a port), so WordPress multisite stores under paths of one host are ONE store for OrcLink: connect each in its own workspace with its own host. The card shows the bound store. If the store moves to a new domain, or the wrong store delivered first, use Allow another store on the card (a manager action, audited): the next order binds it again.
What OrcLink does with an order
| WooCommerce | OrcLink |
|---|---|
completed | order won (paid), value = total |
processing with a paid date that parses to a real date (date_paid_gmt / date_paid; 0000-00-00 00:00:00, n/a and empty are not a date) | order won (paid) |
processing with no paid date (cash on delivery, cheque, bank transfer) | order open, no revenue; it becomes won at completed |
pending, on-hold, failed | order open |
cancelled | cancelled |
refunded | won, net value 0 (each refunds[] entry is a revision) |
a partial refund (refunds[].total, negative) | a revision that lowers net value |
trash, drafts, order.deleted | ignored |
| any other status (a custom status plugin) | ignored; the integration shows a fixed note |
Not built: link claims for WooCommerce orders (only the canonical order outcome and the stage relay), and any retry of a failed delivery (WooCommerce has none; see above).
Check before you trust it: whether WooCommerce sets a paid date when a cash-on-delivery order enters processing is unverified. Place one real COD order and one card order and look at date_paid in the webhook payload before relying on the adapter.