{"id":326947,"date":"2026-06-18T07:52:48","date_gmt":"2026-06-18T07:52:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/kalicart-bridge\/"},"modified":"2026-07-22T07:06:25","modified_gmt":"2026-07-22T07:06:25","slug":"kalicart-bridge","status":"publish","type":"plugin","link":"https:\/\/ary.wordpress.org\/plugins\/kalicart-bridge\/","author":23482077,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.123","stable_tag":"1.0.123","tested":"7.0.2","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"KaliCart Bridge \u2013 Product Feed for ChatGPT & AI Agents","header_author":"KaliCart","header_description":"Makes your WooCommerce catalog machine-readable and agent-accessible. Exposes normalized product data via REST API \u2014 no LLM, no external service, no cloud dependency.","assets_banners_color":"0074f4","last_updated":"2026-07-22 07:06:25","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/bridge.kalicart.com","header_author_uri":"https:\/\/kalicart.com","rating":5,"author_block_rating":0,"active_installs":0,"downloads":758,"num_ratings":2,"support_threads":1,"support_threads_resolved":1,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.100":{"tag":"1.0.100","author":"carthub","date":"2026-06-18 07:52:18"},"1.0.101":{"tag":"1.0.101","author":"carthub","date":"2026-06-18 09:03:11"},"1.0.102":{"tag":"1.0.102","author":"carthub","date":"2026-06-19 14:43:42"},"1.0.103":{"tag":"1.0.103","author":"carthub","date":"2026-06-21 19:02:01"},"1.0.104":{"tag":"1.0.104","author":"carthub","date":"2026-06-23 13:18:41"},"1.0.105":{"tag":"1.0.105","author":"carthub","date":"2026-06-24 06:23:35"},"1.0.106":{"tag":"1.0.106","author":"carthub","date":"2026-06-24 10:16:58"},"1.0.107":{"tag":"1.0.107","author":"carthub","date":"2026-06-25 13:30:02"},"1.0.108":{"tag":"1.0.108","author":"carthub","date":"2026-06-26 14:42:16"},"1.0.109":{"tag":"1.0.109","author":"carthub","date":"2026-06-27 18:39:18"},"1.0.110":{"tag":"1.0.110","author":"carthub","date":"2026-07-02 08:37:35"},"1.0.111":{"tag":"1.0.111","author":"carthub","date":"2026-07-02 11:45:22"},"1.0.112":{"tag":"1.0.112","author":"carthub","date":"2026-07-02 20:49:03"},"1.0.113":{"tag":"1.0.113","author":"carthub","date":"2026-07-03 13:03:31"},"1.0.114":{"tag":"1.0.114","author":"carthub","date":"2026-07-04 11:51:59"},"1.0.115":{"tag":"1.0.115","author":"carthub","date":"2026-07-10 13:25:41"},"1.0.116":{"tag":"1.0.116","author":"carthub","date":"2026-07-11 17:55:13"},"1.0.117":{"tag":"1.0.117","author":"carthub","date":"2026-07-12 13:06:42"},"1.0.118":{"tag":"1.0.118","author":"carthub","date":"2026-07-13 06:53:49"},"1.0.119":{"tag":"1.0.119","author":"carthub","date":"2026-07-14 08:43:34"},"1.0.120":{"tag":"1.0.120","author":"carthub","date":"2026-07-14 10:40:44"},"1.0.123":{"tag":"1.0.123","author":"carthub","date":"2026-07-22 07:06:25"}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3576832,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3576832,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3576832,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3576832,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.100","1.0.101","1.0.102","1.0.103","1.0.104","1.0.105","1.0.106","1.0.107","1.0.108","1.0.109","1.0.110","1.0.111","1.0.112","1.0.113","1.0.114","1.0.115","1.0.116","1.0.117","1.0.118","1.0.119","1.0.120","1.0.123"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[250436,246305,216196,5418,286],"plugin_category":[45],"plugin_contributors":[261605],"plugin_business_model":[],"class_list":["post-326947","plugin","type-plugin","status-publish","hentry","plugin_tags-agentic-commerce","plugin_tags-ai-agents","plugin_tags-chatgpt","plugin_tags-product-feed","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_contributors-carthub","plugin_committers-carthub"],"banners":{"banner":"https:\/\/ps.w.org\/kalicart-bridge\/assets\/banner-772x250.png?rev=3576832","banner_2x":"https:\/\/ps.w.org\/kalicart-bridge\/assets\/banner-1544x500.png?rev=3576832","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/kalicart-bridge\/assets\/icon-128x128.png?rev=3576832","icon_2x":"https:\/\/ps.w.org\/kalicart-bridge\/assets\/icon-256x256.png?rev=3576832","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Make your WooCommerce catalog ready to be read and verified by AI shopping systems.<\/p>\n\n<p>KaliCart Bridge gives you an immediate catalog-readiness report inside WooCommerce: it identifies products with missing images, brand, usable description, category, price or SKU, and links you directly to the native Products screen to fix them. It then exposes your live catalog in a structured form for AI agents and can generate a validated product feed ready for ChatGPT merchant submission.<\/p>\n\n<p>No LLM runs on your site. No cloud service or customer data is sent anywhere by default. Prices, availability and product changes remain live on your WooCommerce store.<\/p>\n\n<p>The plugin does not promise traffic, ChatGPT placement or merchant approval. It prepares and exposes your catalog; OpenAI controls access to its own shopping surfaces and delivery channel.<\/p>\n\n<p><strong>What you get after installation<\/strong><\/p>\n\n<ul>\n<li>A catalog-readiness report with actionable product fixes.<\/li>\n<li>A current, structured catalog API for agents that reach your store.<\/li>\n<li>An optional ChatGPT feed, validated before export.<\/li>\n<li>Optional inclusion in KaliCart's federated catalog, only with explicit consent.<\/li>\n<\/ul>\n\n<p>Documentation: https:\/\/bridge.kalicart.com\/docs\/<\/p>\n\n<p><strong>For developers and AI integrations<\/strong><\/p>\n\n<p><strong>What it does:<\/strong><\/p>\n\n<ul>\n<li>Exposes a <code>\/discovery<\/code> endpoint \u2014 the single entry point any agent needs to understand your catalog<\/li>\n<li>Provides <code>\/catalog\/search<\/code>, <code>\/catalog\/products<\/code>, <code>\/catalog\/product\/{id}<\/code>, <code>\/catalog\/categories<\/code> endpoints<\/li>\n<li>Exposes a Model Context Protocol (MCP) server at <code>\/wp-json\/kalicart\/v1\/mcp<\/code> (JSON-RPC 2.0) so MCP-capable agents can call the catalog as tools \u2014 same data as the REST endpoints, no API key<\/li>\n<li>Gives AI chatbot and assistant builders a structured catalog source to ingest or call, instead of scraping product pages<\/li>\n<li>Computationally normalizes product data: prices (min\/max for variables, sale %, discount), stock, gender inference, color family mapping, size type detection<\/li>\n<li>Exposes WooCommerce shipping-zone policy for agent reasoning; checkout remains the final authority for exact destination\/cart shipping cost<\/li>\n<li>Exposes active product\/category-compatible coupons as conditional checkout savings; coupons never replace the catalog price<\/li>\n<li>Category tree nodes include direct <code>products_url<\/code> and <code>search_url_template<\/code> fields so agents can navigate without constructing URLs manually<\/li>\n<li>Dashboard issue cards and suggestions link to filtered product lists for direct remediation<\/li>\n<li>Uses <strong>your merchant taxonomy<\/strong> \u2014 no global remapping, products stay in your WooCommerce categories<\/li>\n<li>Injects a <code>&lt;link rel=\"kalicart-agent\"&gt;<\/code> in your site <code>&lt;head&gt;<\/code> for agent auto-discovery<\/li>\n<li>Adds an \"agent ready\" badge in the footer<\/li>\n<li>Injects <code>Allow: \/wp-json\/kalicart\/<\/code> in <code>robots.txt<\/code><\/li>\n<li>Generates <code>\/kalicart-sitemap.xml<\/code> linked from the WP sitemap index<\/li>\n<li>Shows a catalog health dashboard in wp-admin with quarantine tracking and improvement suggestions<\/li>\n<\/ul>\n\n<p><strong>What it does NOT do:<\/strong><\/p>\n\n<ul>\n<li>No LLM calls<\/li>\n<li>No cloud dependency for core functionality<\/li>\n<li>No data sent anywhere outside your server by default \u2014 the only optional exception is the Federated Catalog feature (see \"External services\" below), which you turn on explicitly<\/li>\n<li>No API key required for public endpoints<\/li>\n<\/ul>\n\n<p><strong>Normalization engine:<\/strong><\/p>\n\n<ul>\n<li>Price: regular, sale, current, discount %, currency \u2014 variable products get min\/max ranges<\/li>\n<li>Stock: status, in_stock bool, quantity if managed, backorder policy<\/li>\n<li>Gender: inferred from <code>pa_gender<\/code> attribute, category paths, tags, product name (multilingual keywords: IT\/EN\/FR\/DE\/ES)<\/li>\n<li>Color: mapped to 13 color families via keyword matching on <code>pa_color<\/code>\/<code>pa_colore<\/code> and product metadata<\/li>\n<li>Size: detected from <code>pa_size<\/code>\/<code>pa_taglia<\/code>, type auto-detected (clothing S\/M\/L, numeric EU, shoes EU half-sizes)<\/li>\n<\/ul>\n\n<p><strong>Catalog health \/ quarantine:<\/strong><\/p>\n\n<p>Products are scored 0\u2013100 based on: title quality, description length, category assignment, price validity, image presence and SKU presence. Quarantine is reserved for blocking computability issues: ambiguous\/too-short titles, missing or very short descriptions, missing real categories, and missing or zero prices. Missing images and SKUs remain clickable improvement suggestions but do not quarantine products.<\/p>\n\n<p><strong>Checkout sessions (optional):<\/strong><\/p>\n\n<p>When enabled in WP Admin \u2192 KaliCart \u2192 Settings, agents can create checkout sessions containing one or more products. Each session returns cart_url (lands on WooCommerce cart for review) and checkout_url (goes directly to checkout). Sessions expire after 30 minutes. No OAuth, no PII, no payment on the agent side.<\/p>\n\n<p><strong>Model Context Protocol (MCP) endpoint:<\/strong><\/p>\n\n<p>The same read-only catalog is also exposed as an MCP server at <code>\/wp-json\/kalicart\/v1\/mcp<\/code> (JSON-RPC 2.0 over HTTP POST). MCP-capable agents and assistants connect to it and call the catalog as tools: <code>search_products<\/code>, <code>list_products<\/code>, <code>get_product<\/code>, <code>list_categories<\/code>, <code>get_meta<\/code>. It is read-only and needs no authentication, exactly like the public REST endpoints \u2014 it adds a second transport, not new data. No LLM, no external calls. Checkout and payment are never exposed over MCP.<\/p>\n\n<h3>ChatGPT Product Discovery Feed<\/h3>\n\n<ol>\n<li><strong>Configure and generate.<\/strong> Set your return policy URL and target countries (derived from your WooCommerce selling locations); optionally set a brand fallback for own-label stores. The plugin validates every row against the OpenAI Product Feed specification: incomplete store configuration blocks generation entirely, products without image or brand are excluded and counted, and a failed run never destroys the last valid feed.<\/li>\n<li><strong>Apply at chatgpt.com\/merchants.<\/strong> Application and approval are required and decided by OpenAI.<\/li>\n<li><strong>Deliver after approval.<\/strong> Upload the generated file (stable filename, <code>jsonl.gz<\/code> supported) on the delivery channel OpenAI assigns. The plugin regenerates a full daily snapshot via WP-Cron.<\/li>\n<\/ol>\n\n<p>No acceptance or visibility is guaranteed by the plugin: approval, delivery access and final ranking are determined by OpenAI.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin works fully standalone. It connects to one external service <strong>only if you explicitly opt in<\/strong> by activating the optional Federated Catalog feature in WP Admin \u2192 KaliCart Bridge.<\/p>\n\n<p><strong>Service:<\/strong> KaliCart Global (https:\/\/dashboard.kalicart.com)<\/p>\n\n<p><strong>When data is sent:<\/strong> Only when an administrator clicks \"Activate Federated Catalog\" (and, symmetrically, \"Revoke consent\"). Nothing is sent automatically, on activation, or in the background. With the feature off, the plugin makes no external requests.<\/p>\n\n<p><strong>What is sent:<\/strong> A single value \u2014 your site's public URL (e.g. https:\/\/yourstore.com). On revoke, the same URL is sent to withdraw. No customer data, orders, personal data, credentials, or API keys are ever transmitted.<\/p>\n\n<p><strong>What the service does:<\/strong> The URL tells KaliCart Global your store wishes to be discovered. KaliCart Global then periodically reads your already-public catalog (the same data exposed by the Bridge's public REST endpoints) and includes it in federated agent search. It only reads; it never writes to your store. Revoking stops this and parks your catalog.<\/p>\n\n<p><strong>Privacy notice:<\/strong> https:\/\/bridge.kalicart.com\/privacy\/\n<strong>Terms \/ documentation:<\/strong> https:\/\/bridge.kalicart.com\/docs\/<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to <code>\/wp-content\/plugins\/kalicart-bridge\/<\/code><\/li>\n<li>Activate the plugin through the Plugins screen in WordPress<\/li>\n<li>Navigate to <strong>KaliCart<\/strong> in the admin menu<\/li>\n<li>The catalog is immediately accessible at <code>yourdomain.com\/wp-json\/kalicart\/v1\/discovery<\/code><\/li>\n<li>MCP-capable agents can connect to the MCP server at <code>yourdomain.com\/wp-json\/kalicart\/v1\/mcp<\/code><\/li>\n<\/ol>\n\n<p>Full operational documentation is always available at <code>https:\/\/bridge.kalicart.com\/docs\/<\/code>.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20the%20chatgpt%20feed%20work%20outside%20the%20u.s.%3F\"><h3>Does the ChatGPT feed work outside the U.S.?<\/h3><\/dt>\n<dd><p>The feed format is region-neutral. Merchant eligibility and shopping-surface availability are determined by OpenAI and may vary by market.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20handle%20checkout%3F\"><h3>Does the plugin handle checkout?<\/h3><\/dt>\n<dd><p>No, by design. The feed is discovery-only (<code>is_eligible_checkout=false<\/code>): customers buy on your storefront and you remain merchant of record. This matches OpenAI's own shift toward merchant-owned checkout.<\/p><\/dd>\n<dt id=\"does%20this%20share%20my%20data%20with%20kalicart%20or%20any%20third%20party%3F\"><h3>Does this share my data with KaliCart or any third party?<\/h3><\/dt>\n<dd><p>Not unless you choose to. By default the plugin runs entirely on your server and sends nothing externally. The only exception is the optional Federated Catalog feature: if you explicitly activate it, the plugin sends your store's public URL (and nothing else) to KaliCart Global so your public catalog can be included in federated agent search. No customer, order, or private data is ever sent. See \"External services\" below, and the privacy notice at https:\/\/bridge.kalicart.com\/privacy\/.<\/p><\/dd>\n<dt id=\"do%20i%20need%20a%20kalicart%20account%3F\"><h3>Do I need a KaliCart account?<\/h3><\/dt>\n<dd><p>No. This plugin is fully standalone and free.<\/p><\/dd>\n<dt id=\"what%20is%20the%20federated%20catalog%3F\"><h3>What is the Federated Catalog?<\/h3><\/dt>\n<dd><p>The Federated Catalog is an optional discovery network operated by KaliCart Global. The Bridge makes your catalog readable by agents that already reach your domain; the Federated Catalog makes it discoverable by agents that do not know your store yet. It is opt-in, separate from the local Bridge endpoints, and revocable at any time.<\/p>\n\n<p>There are two discovery paths. Local signals \u2014 <code>.well-known<\/code> files, robots.txt entries, the <code>rel=\"kalicart-agent\"<\/code> head link and the badge \u2014 help an agent that lands on your own domain find the Bridge. They do not feed the federated index by themselves. The federated index is a separate cross-merchant index: after you activate it, KaliCart Global reads your already-public <code>\/discovery<\/code> and <code>\/catalog\/*<\/code> endpoints and lets agents search across participating stores.<\/p>\n\n<p>End to end: from WP Admin \u2192 KaliCart Bridge you activate the Federated Catalog; the plugin sends only your public site URL; KaliCart Global pulls the public catalog read-only; matching results route agents back to your store. Authoritative price, availability and checkout stay on your WooCommerce site, served live by your Bridge. If you revoke consent, your catalog leaves federated results while direct agent access to your store remains active.<\/p><\/dd>\n<dt id=\"who%20can%20access%20the%20catalog%20endpoints%3F\"><h3>Who can access the catalog endpoints?<\/h3><\/dt>\n<dd><p>Public endpoints (discovery, search, products, categories) are accessible without authentication \u2014 same as the WooCommerce REST API public surfaces. The <code>\/health<\/code> endpoint requires <code>manage_woocommerce<\/code> capability.<\/p><\/dd>\n<dt id=\"can%20i%20disable%20the%20badge%20or%20robots.txt%20injection%3F\"><h3>Can I disable the badge or robots.txt injection?<\/h3><\/dt>\n<dd><p>Yes \u2014 all three signals (badge, robots.txt, sitemap) can be toggled individually in the KaliCart settings tab.<\/p><\/dd>\n<dt id=\"how%20often%20is%20the%20health%20report%20cached%3F\"><h3>How often is the health report cached?<\/h3><\/dt>\n<dd><p>5 minutes. You can force a refresh via the \"Refresh analysis\" button or the <code>?force=true<\/code> query parameter on the <code>\/health<\/code> endpoint.<\/p><\/dd>\n<dt id=\"how%20do%20i%20connect%20this%20to%20an%20ai%20assistant%20or%20mcp%20client%3F\"><h3>How do I connect this to an AI assistant or MCP client?<\/h3><\/dt>\n<dd><p>The catalog can be consumed two ways. Any agent can call the plain REST endpoints under <code>\/wp-json\/kalicart\/v1\/catalog\/<\/code> directly. MCP-capable clients can instead connect to the MCP server at <code>\/wp-json\/kalicart\/v1\/mcp<\/code> (JSON-RPC 2.0): the assistant connects to that URL \u2014 no API key \u2014 and gains the catalog tools (search_products, get_product, list_categories, get_meta, list_products). In clients that support remote MCP connectors, add it as a custom connector pointing to that URL.<\/p><\/dd>\n<dt id=\"can%20woocommerce%20chatbot%20services%20use%20the%20bridge%3F\"><h3>Can WooCommerce chatbot services use the Bridge?<\/h3><\/dt>\n<dd><p>Yes, when the chatbot service can ingest URLs, API documents or external knowledge sources. Give it the discovery URL first: <code>https:\/\/yourdomain.com\/wp-json\/kalicart\/v1\/discovery<\/code>. From there it can find the catalog endpoints, the OpenAPI description and the MCP endpoint. If the service supports live REST or MCP calls, it can query current catalog data directly. If it only imports a knowledge base, it may create a snapshot: useful for product answers, but final price, stock, coupons, shipping and checkout should still be verified on the merchant site.<\/p>\n\n<p>The benefit is practical: chatbot builders can read a structured, machine-readable WooCommerce catalog instead of scraping product pages. The Bridge does not add an LLM to your site and does not decide how the chatbot works; it supplies cleaner catalog data for tools that can consume it.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.123<\/h4>\n\n<ul>\n<li>Distribution: returns KaliCart Bridge to WordPress.org from the approved 1.0.120 baseline. Versions 1.0.121 and 1.0.122 were distributed externally and are superseded by this release.<\/li>\n<li>Updates: removes the custom Update URI, standalone updater and external plugin-details override. Future updates are provided by WordPress.org.<\/li>\n<li>Privacy and federation: restores the explicit opt-in and revocation flow approved in 1.0.120. The upgrade removes only the automatic 1.0.122 lifecycle job and its technical retry state; merchant settings are preserved.<\/li>\n<li>Compatibility: installs running 1.0.120, 1.0.121 or 1.0.122 converge on the same WordPress.org-compatible package without changes to catalog, feed, MCP or checkout behavior.<\/li>\n<li>Housekeeping: shortens the directory changelog so WordPress.org can display it without truncation.<\/li>\n<\/ul>\n\n<h4>1.0.122<\/h4>\n\n<ul>\n<li>External-only release: briefly introduced an automatic federation lifecycle and Bridge-hosted plugin-details metadata. It was never published on WordPress.org and is superseded by 1.0.123, which restores explicit merchant consent and the native WordPress.org update flow.<\/li>\n<\/ul>\n\n<h4>1.0.121<\/h4>\n\n<ul>\n<li>External-only release: introduced a standalone HTTPS updater for installations outside WordPress.org. It was never published on WordPress.org and is superseded by 1.0.123; the standalone updater is removed after convergence.<\/li>\n<\/ul>\n\n<h4>1.0.120<\/h4>\n\n<ul>\n<li>Discovery controls: the three storefront-link toggles are independent, accurately described and remain off by default on new installations.<\/li>\n<li>Catalog accuracy: size is explicitly detail-only and unsupported as a parent-product search filter; agents must verify purchasable product variations.<\/li>\n<li>Price metadata: catalog ranges use WooCommerce's public product lookup and lowest-sale statistics include only currently active, public sale entities.<\/li>\n<li>Lifecycle: reactivation preserves merchant settings; disabling or deactivating discovery removes only Bridge-owned .well-known files and disabled routes return 404.<\/li>\n<li>OpenAPI: price sale scope, variant discount counts and catalog deal statistics are now explicitly typed.<\/li>\n<\/ul>\n\n<h4>1.0.119<\/h4>\n\n<ul>\n<li>Checkout privacy: all checkout-session REST responses now send private no-store headers, preventing reverse proxies from serving stale bearer-session data after cancellation or expiry. Discovery now documents the real pending and cart_loaded states.<\/li>\n<li>Variable sales: product summaries distinguish some_variants from all_variants, report discounted and priced variation counts, and require selected-variation verification when only particular sizes or colors are discounted. The calculation reuses WooCommerce's existing variation price matrix and adds no per-variation queries.<\/li>\n<li>Sale statistics: catalog metadata now separates product cards on sale from individually discounted variations while retaining on_sale_total as the product-level compatibility field.<\/li>\n<li>Catalog accuracy: products without a usable price remain discoverable but sort after priced products, so ascending price pages no longer fill with zero-price placeholders.<\/li>\n<li>Performance: a missing facet snapshot queues a background rebuild instead of scanning the full catalog during a public request. Saving unrelated settings no longer flushes rewrite rules.<\/li>\n<li>Lifecycle hardening: deactivation clears recurring jobs; uninstall removes all Bridge options, dynamic facets, scheduled feed work, generated catalog feeds and plugin-owned public discovery mirrors.<\/li>\n<\/ul>\n\n<h4>1.0.118<\/h4>\n\n<ul>\n<li>New: checkout attribution. Orders created from a Bridge checkout session \u2014 through either classic checkout or Checkout Block \u2014 are linked back to that session. A local 30-day funnel (sessions created, carts loaded, orders linked and net paid value) is shown in the Stats tab of the Bridge dashboard. No data is sent to the cloud.<\/li>\n<li>Accuracy: net paid value includes only linked orders for which WooCommerce has recorded a payment date, net of refunds. Cash on delivery, bank transfer and cheque orders are excluded unless WooCommerce records an actual payment confirmation.<\/li>\n<li>Checkout integrity: attribution is written only when the live order still matches the exact product, variation and quantity fingerprint loaded by the Bridge. Cart mutations and partial\/failed loads clear attribution; direct variation IDs are normalized correctly; each session can claim at most one order atomically. Reused links return a generic HTTP 410 without exposing the original order.<\/li>\n<li>Checkout hardening: the opt-in session endpoint now enforces a pre-parser JSON body limit, strict integer inputs, 20-line and aggregate-quantity ceilings, WooCommerce purchase limits, short weighted request limits and a longer storage budget. GET, DELETE and checkout links are also bounded. Proxy forwarding is trusted only from a configurable allowlist and parsed fail-closed.<\/li>\n<li>Idempotency: concurrent requests with the same Idempotency-Key are serialized through fixed, bounded database buckets. The original public 201 response is replayed without internal attribution fields; conflicting payloads and unavailable originals cannot create a duplicate session.<\/li>\n<li>MCP hardening: the server now declares only MCP 2025-06-18, rejects JSON-RPC batches and invalid object shapes\/types, validates tool schemas without coercion, enforces JSON Content-Type, Origin, protocol header and body bounds before parsing, and weights catalog work in its abuse budget.<\/li>\n<li>Catalog security and performance: public discovery\/catalog work uses proxy-safe weighted limits; expensive derived filters run in bounded batches with an explicit candidate ceiling; variable-product price filters are verified against price.current after a WooCommerce lookup-table prefilter; repeated compact derived queries use one size-bounded short cache.<\/li>\n<li>Telemetry and maintenance: concurrent local counters no longer lose increments; rejected requests, MCP metadata and checkout paths do not amplify telemetry writes; storefront HTML telemetry is branded-agent-only and bounded by default. Fixed and dynamic security state, claims, legacy sessions and caches are cleaned on expiry\/uninstall.<\/li>\n<\/ul>\n\n<h4>1.0.117<\/h4>\n\n<ul>\n<li>New: \"Check external visibility\" in the Federated Catalog panel. Shows what KaliCart Global observed from outside the last time it probed your \/discovery endpoint \u2014 the same reachability an external agent depends on. Clearly labeled as a snapshot (not a live scan), scoped to discovery reachability only, with a staleness warning past 7 days. Read-only: does not trigger a new probe or change federation consent.<\/li>\n<\/ul>\n\n<h4>1.0.116<\/h4>\n\n<ul>\n<li>New: POST \/checkout\/session honors an optional Idempotency-Key header. Retrying with the same key and payload returns the original session instead of creating a duplicate; reusing a key with a different payload returns 409. Hardens agent retries and double-submits on an existing endpoint.<\/li>\n<\/ul>\n\n<h4>1.0.115<\/h4>\n\n<ul>\n<li>Fix: products whose description is empty markup (empty paragraph, <code>&amp;nbsp;<\/code>, non-breaking space) are no longer dropped from the ChatGPT feed. The product name is used as a fallback, and entity-only descriptions no longer leak into the feed. Plain-text extraction now decodes HTML entities.<\/li>\n<li>Change: the AI catalog badge is now off by default on new installs. Existing installs and merchant choices are preserved across updates.<\/li>\n<li>New: ChatGPT feed readiness reports how many rows were sent with the product name in place of a real description.<\/li>\n<li>The validator's excluded-row count is now always shown in the feed snapshot summary.<\/li>\n<li>Readme: Description rewritten to lead with the catalog-readiness report; technical details grouped under \"For developers and AI integrations\".<\/li>\n<\/ul>\n\n<h4>1.0.114<\/h4>\n\n<ul>\n<li>Quality Signals: the Quarantine tab renamed and rebuilt for large catalogs - honest sample (the most recent 100, with full counts and a visible note), plus per-problem filter buttons that open the native Products list pre-filtered (bulk and quick edit for free)<\/li>\n<li>New Products-list filters: short titles, no description, no category, no price, no SKU - served from the cached health report, so button counts and list contents always match<\/li>\n<li>Clarified in the UI: nothing in Quality Signals is blocked or hidden - products stay fully served to agents with their issues declared as quality flags and score, which agents can weigh<\/li>\n<li>Overview: new suggestion for products without a brand - not required by the agent-readable catalog, search or MCP, but required by the ChatGPT product feed specification<\/li>\n<li>Signals cleanup: removed the api-catalog head link and its robots.txt entry (the extensionless \/.well-known path returns 404 on most hosting setups); the discovery and OpenAPI links remain, and the physical api-catalog.json file stays served for clients that probe it<\/li>\n<\/ul>\n\n<h4>1.0.113<\/h4>\n\n<ul>\n<li>Performance - ChatGPT feed generation is dramatically faster on large catalogs: product data is now batch-primed (posts, meta and terms per page, variations included), collapsing thousands of per-product queries; catalogs that previously took ~20 seconds generate in a fraction of that, and very large catalogs no longer risk PHP execution-time limits<\/li>\n<li>ChatGPT Feed - the tab is now named for what it is; single \"Save and generate\/validate now\" action (the separate save-only button always left an unverified state), with a progress spinner while the snapshot is generated<\/li>\n<li>Fix - saving settings now reliably regenerates the feed: generation no longer depends on the submit button's own value, which browsers omit when submitting with the Enter key<\/li>\n<li>Fallback brand - the \"Fallback applied\" readiness state is now a soft amber notice instead of red: with the merchant's explicit declaration it is a legitimate configuration for own-label stores, not an error<\/li>\n<li>Translations - fixed five interface strings per language that silently rendered in English at runtime (Italian, French, German, Spanish are now fully translated end to end)<\/li>\n<li>Housekeeping - the optional \"Agent entry-point page\" shortcode section has been retired from Settings and from the discovery document: real-world telemetry showed agents use the structured discovery signals, not HTML directory pages. Existing pages using the shortcode keep rendering unchanged<\/li>\n<\/ul>\n\n<h4>1.0.112<\/h4>\n\n<ul>\n<li>Agent Commerce - the ChatGPT feed now lives in a dedicated Agent Commerce tab inside the plugin dashboard, with a readiness checklist (return policy, countries, brand, images, schema validation, daily refresh, delivery status), live data-gap counts with one-click access to the pre-filtered Products list and a full CSV export, and a step-by-step guide to OpenAI's application and delivery workflow<\/li>\n<li>ChatGPT feed - missing brand is no longer blocking: rows enter the file without the brand field (never an empty or fabricated value) and are counted and flagged, with an explicit notice that OpenAI may reject them and that the merchant submits them under their own responsibility; products without a primary image remain excluded as the specification requires<\/li>\n<li>Catalog - the merchant-declared brand (WooCommerce Brands taxonomy, Perfect Brands or brand attributes) is now exposed across every surface: product detail, search summaries, full records, OpenAPI schemas and the ChatGPT feed, from a single resolver; HTML entities in brand names are decoded everywhere<\/li>\n<li>Interface - the new tab fully adopts the plugin design system (cards, buttons, toggle, status pills, flex-row lists instead of tables)<\/li>\n<li>Translations - the entire Agent Commerce experience is fully translated in all shipped locales: Italian, French, German and Spanish<\/li>\n<\/ul>\n\n<h4>1.0.111<\/h4>\n\n<ul>\n<li>ChatGPT product discovery - new OpenAI-compatible product feed generator (ACP file-upload specification): per-row schema validator as a hard gate (every emitted row is conformant), atomic snapshot swap that preserves the last valid feed on any failure, global configuration gate (return policy, countries), honest exclusion counts for products missing image or brand, stable filename ready for the delivery channel OpenAI assigns after merchant approval<\/li>\n<li>Feed admin - new ChatGPT Shopping page with readiness statistics, exclusion counts, feed downloads and settings: opt-in brand fallback for own-label stores, return policy URL (defaults to your Refund and Returns page), target countries derived from WooCommerce selling locations<\/li>\n<\/ul>\n\n<h4>1.0.110<\/h4>\n\n<ul>\n<li>Scraper-facing discovery - an HTML comment at the top of every page and an HTTP Link header (rel=\"kalicart-agent\") now point AI agents to the structured catalog in the very surfaces they scrape; validated in blind agent tests (3\/3 autonomous discovery vs 0\/1 without these signals)<\/li>\n<li>MCP handshake - \/mcp\/.well-known\/oauth-protected-resource now answers with RFC 9728 Protected Resource Metadata carrying an empty authorization_servers list, telling MCP clients explicitly that this keyless server requires no OAuth instead of a 404 they must interpret<\/li>\n<li>Agent traffic insight - new opt-out telemetry counts daily agent traffic per surface (storefront HTML, catalog REST, MCP) with client classification (branded agents, anonymous programmatic, generic clients, browsers), API route and status breakdown, and MCP client identity, method, tool and outcome from the protocol handshake; server-internal and health-check traffic is excluded; data stays local in a single option, 31-day retention<\/li>\n<li>OpenAPI accuracy - the fields parameter is now documented per endpoint (search defaults to summary; products defaults to full and switches to summary when filters are present) and a ProductSummary schema describes the slim projection, so OpenAPI-driven clients no longer read summary responses as missing fields<\/li>\n<li>Agent instructions - step 5 now names \/catalog\/search and \/catalog\/products explicitly for summary-based triage<\/li>\n<\/ul>\n\n<h4>Earlier releases<\/h4>\n\n<ul>\n<li>Release notes older than 1.0.110 are omitted from the WordPress.org directory changelog.<\/li>\n<\/ul>","raw_excerpt":"Validated OpenAI-compatible product feed for ChatGPT product discovery (ACP), plus catalog API, MCP server and UCP discovery for AI agents.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/326947","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=326947"}],"author":[{"embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/carthub"}],"wp:attachment":[{"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=326947"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=326947"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=326947"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=326947"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=326947"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ary.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=326947"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}