Title: ShopMobi – API Optimizer for WooCommerce
Author: hammadev2
Published: <strong>18. junija 2026</strong>
Last modified: 30. septembra 2026

---

Tykace pytaś

![](https://ps.w.org/api-optimizer-for-woocommerce/assets/banner-772x250.png?rev
=3720798)

![](https://ps.w.org/api-optimizer-for-woocommerce/assets/icon-256x256.png?rev=3720798)

# ShopMobi – API Optimizer for WooCommerce

 Wót [hammadev2](https://profiles.wordpress.org/hammadev2/)

[Ześěgnuś](https://downloads.wordpress.org/plugin/api-optimizer-for-woocommerce.1.0.0.zip)

 * [Drobnostki](https://dsb.wordpress.org/plugins/api-optimizer-for-woocommerce/#description)
 * [Pógódnośenja](https://dsb.wordpress.org/plugins/api-optimizer-for-woocommerce/#reviews)
 *  [Instalacija](https://dsb.wordpress.org/plugins/api-optimizer-for-woocommerce/#installation)
 * [Wuwiśe](https://dsb.wordpress.org/plugins/api-optimizer-for-woocommerce/#developers)

 [Pódpěra](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/)

## Wopisanje

Building an SPA or mobile app on WooCommerce? Stop receiving 50+ fields when your
screen needs 3 — and stop stitching together a JWT plugin, a filtering snippet, 
and a Stripe integration to get there.

ShopMobi is an all-in-one WooCommerce REST API layer for developers building **single-
page apps, Flutter apps, React Native apps, or any headless WooCommerce frontend**.
It ships two things:

 1. **Field Filtering** — trim the responses of the _existing_ WooCommerce `wc/v3` 
    endpoints (products, variations, orders, customers). No new routes: you keep calling
    the standard WooCommerce REST API and opt into smaller responses.
 2. **Custom Endpoints** — ready-made routes under `shopmobi/v1` for login, registration,
    password reset, store settings, and Stripe payments.

📖 **Full API reference with every request, response and error code:** [GitHub documentation](https://github.com/hammadev/woocommerce-api-optimizer#readme)

#### At a Glance

Same endpoint, same credentials, one query parameter added:

    ```
    GET /wp-json/wc/v3/products/101?fields=id,name,price
    ```

 * **Fields returned per product:** 66 by default  only the ones you ask for
 * **Payload for one product:** ~2.8 KB  ~130 B
 * **Payload for a 20-product listing screen:** ~56 KB  ~2.5 KB
 * **New endpoints to learn:** none — it’s the same `wc/v3` route

#### Why ShopMobi?

 * **One plugin instead of three.** A headless WooCommerce frontend usually needs
   a JWT/auth plugin, hand-written response-filtering code, and a separate Stripe
   integration. ShopMobi ships all of it as one tested package.
 * **Built for SPA and mobile clients.** Flutter, React Native, and native apps 
   pay for every extra byte in load time, memory, and mobile data. A product screen
   that needs 4 fields shouldn’t download 60+.
 * **GraphQL-like control without leaving REST.** Pick exactly the fields you want,
   per request — no schema, no query language, no extra server.
 * **Auth, password reset, and Stripe included.** Login, registration, profile updates,
   password reset, and Stripe `PaymentIntent` / `EphemeralKey` creation are ready
   to use, so you don’t build and secure them yourself.

#### Field Filtering

Add an **include list** or an **exclude list** to any supported `wc/v3` request,
as a header or a query parameter:

 * **Include only these fields:** header `X-WC-Fields: id,name,price` or query `?
   fields=id,name,price`
 * **Exclude these fields:** header `X-WC-Except: meta_data` or query `?except_fields
   =meta_data`

How it behaves:

 * WooCommerce builds its normal response first — every hook, permission check, 
   and sanitization rule still runs. ShopMobi only trims the **top-level keys** 
   right before the response is sent.
 * Collections (e.g. a product list) are trimmed item by item, so every item comes
   back in the same shape.
 * If a header and a query parameter are both sent, the **header wins**. If an include
   and an exclude list are both sent, both apply.
 * With an include list, only the listed fields come back — add `id` yourself if
   your app needs it.

Example — only the fields a product list screen needs:

    ```
    curl "https://example.com/wp-json/wc/v3/products?fields=id,name,price,images" \
      -u consumer_key:consumer_secret
    ```

Response (every product in the list is trimmed the same way):

    ```
    [
      {
        "id": 101,
        "name": "Classic T-Shirt",
        "price": "24.00",
        "images": [{ "id": 55, "src": "https://example.com/wp-content/uploads/tshirt.jpg" }]
      }
    ]
    ```

Example — drop heavy fields from orders instead:

    ```
    curl "https://example.com/wp-json/wc/v3/orders?except_fields=meta_data,_links,tax_lines" \
      -u consumer_key:consumer_secret
    ```

**Supported endpoints:** products, product variations, orders, order refunds, and
customers (list and single-item routes).

**Variation enhancement:** product responses return full variation objects instead
of raw variation IDs — pricing, sale status, SKU, stock, attributes, and image URL—
so a product page doesn’t need one extra request per variation.

#### Custom Endpoints

All routes live under `https://your-site.com/wp-json/shopmobi/v1`:

 * `POST /users/login` — log in with username and password (cookie-based, rate limited)
 * `POST /users/register` — create a customer account (rate limited)
 * `POST /users/update-profile` — update name and phone _(requires login)_
 * `POST /users/reset-password/generate` — email a password reset key
 * `POST /users/reset-password/verify` — verify the key and set a new password
 * `GET /general-settings` — store country, currency format, and active payment 
   gateways
 * `GET /store-location` — store address _(requires login)_
 * `GET /payment-gateways` — active payment gateways
 * `POST /stripe-payment` — create a Stripe `PaymentIntent` + `EphemeralKey` for
   Stripe’s mobile `PaymentSheet` _(requires login)_

Endpoints marked _requires login_ need a valid WordPress session: cookie authentication
with an `X-WP-Nonce` header, or [Application Passwords](https://make.wordpress.org/core/2020/11/05/application-passwords-integration-guide/)
over HTTP Basic Auth. `/users/login` sets standard WordPress auth cookies; it does
not return a bearer token.

Request bodies, response examples, and error codes for every endpoint are in the
[GitHub documentation](https://github.com/hammadev/woocommerce-api-optimizer#custom-endpoints).

#### Third-Party Services

This plugin optionally integrates with **Stripe** (https://stripe.com) for payment
processing. The Stripe integration is inactive until you provide API keys under **
WooCommerce > API Optimizer**.

When the `/shopmobi/v1/stripe-payment` endpoint is called, payment data (amount,
currency, Stripe customer ID) is sent directly to Stripe’s servers. No payment data
passes through ShopMobi or any other third party.

 * Stripe Privacy Policy: https://stripe.com/privacy
 * Stripe Terms of Service: https://stripe.com/legal

Your Stripe API keys are stored in your WordPress database and are never shared 
with the plugin author.

#### Privacy

This plugin stores data in your own WordPress database only:

 * **Stripe customer IDs** (`stripe_cust_id` user meta) — created when a user makes
   a Stripe payment, and shared only with Stripe to identify returning customers.
 * **Password reset keys** — handled entirely by WordPress core (`get_password_reset_key()`/`
   reset_password()`).

The plugin does not track users, send analytics, or transmit personal data to ShopMobi
or any third party, except payment data sent directly to Stripe when the Stripe 
endpoint is used.

## Screenshots

[⌊Settings page under WooCommerce > API Optimizer — enter optional Stripe API keys.⌉⌊
Settings page under WooCommerce > API Optimizer — enter optional Stripe API keys
.⌉[

Settings page under WooCommerce > API Optimizer — enter optional Stripe API keys.

[⌊Example: field-filtered product list response returning only id, name, and price.⌉⌊
Example: field-filtered product list response returning only id, name, and price
.⌉[

Example: field-filtered product list response returning only `id`, `name`, and `
price`.

[⌊Example: variation response enriched with full attributes, pricing, and image 
URL.⌉⌊Example: variation response enriched with full attributes, pricing, and image
URL.⌉[

Example: variation response enriched with full attributes, pricing, and image URL.

## Instalacija

#### Standard Installation (Recommended)

 1. Go to **Plugins > Add New > Upload Plugin** in your WordPress admin.
 2. Upload the plugin zip file and click **Install Now**.
 3. Click **Activate Plugin**.
 4. Optionally, go to **WooCommerce > API Optimizer** to enter your Stripe API keys.

#### Installation from Source

 1. Clone the repository and navigate to the plugin folder.
 2. Run: `composer install --no-dev --optimize-autoloader`
 3. Copy the folder to `wp-content/plugins/` and activate from the Plugins screen.

#### Requirements

 * WordPress 5.8 or higher
 * WooCommerce 6.0 or higher
 * PHP 7.4 or higher

## FAQ

### Where is the full API documentation?

Every endpoint, with request bodies, response examples, and error codes, is documented
on [GitHub](https://github.com/hammadev/woocommerce-api-optimizer#readme).

### Does field filtering affect server performance?

The full WooCommerce response is built internally before filtering is applied, so
server processing time is unchanged. The benefit is a smaller network payload for
mobile and headless clients.

### Does this replace the WooCommerce REST API?

No. This plugin adds a filtering layer on top of the standard WooCommerce REST API,
and adds separate custom endpoints under `shopmobi/v1` alongside it. All existing
WooCommerce authentication, permissions, and hooks still apply.

### What happens if I stop using field filtering — is there anything to migrate?

Nothing. Filtering only runs when a request includes `fields` / `X-WC-Fields` or`
except_fields` / `X-WC-Except`. Stop sending those and every endpoint returns WooCommerce’s
normal, full response.

### Can I use both a header and a query parameter at the same time?

The header takes priority. If `X-WC-Fields` is present, the `fields` query parameter
is ignored for that request — same rule for `X-WC-Except` vs `except_fields`.

### Is Stripe required?

No. Stripe is completely optional. All other features — field filtering, auth endpoints,
general settings — work without any Stripe configuration.

### Does this work with WooCommerce HPOS (High-Performance Order Storage)?

Yes. The plugin filters WooCommerce REST API responses and does not make direct 
database queries, so it is fully compatible with HPOS.

### Is the plugin compatible with caching plugins?

The field filtering works on REST API responses. If your caching plugin caches REST
API responses, those cached responses will not be filtered. Disable REST API caching
or configure it to vary by the `X-WC-Fields` / `X-WC-Except` headers.

### Where are Stripe API keys stored?

Stripe API keys are stored in the WordPress options table via the standard WordPress
Settings API (`shopmobi_ao_stripe_secret_key`, `shopmobi_ao_stripe_public_key`).
They are never logged, exposed in source code, or transmitted to any party other
than Stripe.

### Does the plugin collect any data?

The plugin stores the following data in your own WordPress database:

 * Stripe customer IDs in user meta (`stripe_cust_id`) — only when Stripe is used
 * Temporary password reset keys — handled entirely by WordPress core and invalidated
   automatically after use

No data is sent to ShopMobi or any external service other than Stripe (when explicitly
used).

### Can I use this plugin without WooCommerce?

No. WooCommerce must be installed and active. If WooCommerce is not detected, the
plugin will show an admin notice and will not register any hooks or endpoints.

## Reviews

![](https://secure.gravatar.com/avatar/e6f8beaebd52a235f0598c4e8d7046ed161177069a37aa72ce723f39dd9dec47?
s=60&d=retro&r=g)

### 󠀁[Great solution for headless WooCommerce](https://wordpress.org/support/topic/great-solution-for-headless-woocommerce/)󠁿

 [doomsday20](https://profiles.wordpress.org/doomsday20/) 30. septembra 2026

Exactly what I needed for a mobile/SPA project built on WooCommerce. The field filtering
alone cuts down API payloads massively — no more pulling 60+ fields when the app
only needs 3. Having login, password reset, and Stripe endpoints bundled in saved
me from stitching together multiple plugins. Clean documentation on GitHub too. 
Highly recommend for anyone building a headless WooCommerce frontend.

 [ Read all 1 review ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/)

## Sobustatkujuce a wuwijarje

„ShopMobi – API Optimizer for WooCommerce“ jo software wótwórjonego žrědła. Slědujuce
luźe su pśinosowali k toś tomu tykacoju.

Sobustatkujuce

 *   [ hammadev2 ](https://profiles.wordpress.org/hammadev2/)

[Translate “ShopMobi – API Optimizer for WooCommerce” into your language.](https://translate.wordpress.org/projects/wp-plugins/api-optimizer-for-woocommerce)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/api-optimizer-for-woocommerce/),
check out the [SVN repository](https://plugins.svn.wordpress.org/api-optimizer-for-woocommerce/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/api-optimizer-for-woocommerce/)
by [RSS](https://plugins.trac.wordpress.org/log/api-optimizer-for-woocommerce/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release.
 * Field filtering via `X-WC-Fields` / `X-WC-Except` headers and `fields` / `except_fields`
   query parameters.
 * Applies to products, orders, customers, and variation endpoints.
 * Auth endpoints: login, register, update profile.
 * Password reset endpoints: generate and verify.
 * General settings endpoint: country, currency, store location, active gateways.
 * Payment gateways endpoint.
 * Stripe PaymentIntent endpoint with EphemeralKey support.
 * Product variation response enhancer.
 * Admin settings page under WooCommerce > API Optimizer.

## Meta

 *  Version **1.0.0**
 *  Last updated **6 dnjow**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 abo nowša **
 *  Tested up to **7.0.6**
 *  PHP version ** 7.4 abo nowša **
 *  Language
 * [English (US)](https://wordpress.org/plugins/api-optimizer-for-woocommerce/)
 * Tags
 * [headless](https://dsb.wordpress.org/plugins/tags/headless/)[Mobile App](https://dsb.wordpress.org/plugins/tags/mobile-app/)
   [performance](https://dsb.wordpress.org/plugins/tags/performance/)[rest-api](https://dsb.wordpress.org/plugins/tags/rest-api/)
   [woocommerce](https://dsb.wordpress.org/plugins/tags/woocommerce/)
 *  [Rozšyrjony naglěd](https://dsb.wordpress.org/plugins/api-optimizer-for-woocommerce/advanced/)

## Pógódnośenja

 5 out of 5 stars.

 *  [  1 5-star review     ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/reviews/)

## Sobustatkujuce

 *   [ hammadev2 ](https://profiles.wordpress.org/hammadev2/)

## Pódpěra

Got something to say? Need help?

 [Forum pomocy pokazaś](https://wordpress.org/support/plugin/api-optimizer-for-woocommerce/)