{"id":319035,"date":"2026-06-18T11:38:51","date_gmt":"2026-06-18T11:38:51","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/api-optimizer-for-woocommerce\/"},"modified":"2026-09-30T09:32:06","modified_gmt":"2026-09-30T09:32:06","slug":"api-optimizer-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/dsb.wordpress.org\/plugins\/api-optimizer-for-woocommerce\/","author":23505390,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.7","requires":"5.8","requires_php":"7.4","requires_plugins":null,"header_name":"ShopMobi \u2013 API Optimizer for WooCommerce","header_author":"ShopMobi","header_description":"Your store deserves a better API. Stop receiving 50+ fields when your app needs 3. GraphQL-like field filtering over REST, plus login and Stripe payments out of the box.","assets_banners_color":"f7fcfa","last_updated":"2026-09-30 09:32:06","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":5,"author_block_rating":0,"active_installs":0,"downloads":263,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"hammadev2","date":"2026-09-30 09:32:06","revision":3720815}},"upgrade_notice":{"1.0.0":"<p>Initial release \u2014 no upgrade steps required.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3720798,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3720798,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3720798,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3720798,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3577108,"resolution":"1","location":"assets","locale":"","width":1440,"height":900},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3577108,"resolution":"2","location":"assets","locale":"","width":1440,"height":900},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3577108,"resolution":"3","location":"assets","locale":"","width":1440,"height":900}},"screenshots":{"1":"Settings page under WooCommerce &gt; API Optimizer \u2014 enter optional Stripe API keys.","2":"Example: field-filtered product list response returning only <code>id<\/code>, <code>name<\/code>, and <code>price<\/code>.","3":"Example: variation response enriched with full attributes, pricing, and image URL."}},"plugin_section":[],"plugin_tags":[141196,2429,247,23853,286],"plugin_category":[45,54],"plugin_contributors":[267701],"plugin_business_model":[],"class_list":["post-319035","plugin","type-plugin","status-publish","hentry","plugin_tags-headless","plugin_tags-mobile-app","plugin_tags-performance","plugin_tags-rest-api","plugin_tags-woocommerce","plugin_category-ecommerce","plugin_category-security-and-spam-protection","plugin_contributors-hammadev2","plugin_committers-hammadev2"],"banners":{"banner":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/banner-772x250.png?rev=3720798","banner_2x":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/banner-1544x500.png?rev=3720798","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/icon-128x128.png?rev=3720798","icon_2x":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/icon-256x256.png?rev=3720798","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/screenshot-1.png?rev=3577108","caption":"Settings page under WooCommerce &gt; API Optimizer \u2014 enter optional Stripe API keys."},{"src":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/screenshot-2.png?rev=3577108","caption":"Example: field-filtered product list response returning only <code>id<\/code>, <code>name<\/code>, and <code>price<\/code>."},{"src":"https:\/\/ps.w.org\/api-optimizer-for-woocommerce\/assets\/screenshot-3.png?rev=3577108","caption":"Example: variation response enriched with full attributes, pricing, and image URL."}],"raw_content":"<!--section=description-->\n<p>Building an SPA or mobile app on WooCommerce? Stop receiving 50+ fields when your screen needs 3 \u2014 and stop stitching together a JWT plugin, a filtering snippet, and a Stripe integration to get there.<\/p>\n\n<p>ShopMobi is an all-in-one WooCommerce REST API layer for developers building <strong>single-page apps, Flutter apps, React Native apps, or any headless WooCommerce frontend<\/strong>. It ships two things:<\/p>\n\n<ol>\n<li><strong>Field Filtering<\/strong> \u2014 trim the responses of the <em>existing<\/em> WooCommerce <code>wc\/v3<\/code> endpoints (products, variations, orders, customers). No new routes: you keep calling the standard WooCommerce REST API and opt into smaller responses.<\/li>\n<li><strong>Custom Endpoints<\/strong> \u2014 ready-made routes under <code>shopmobi\/v1<\/code> for login, registration, password reset, store settings, and Stripe payments.<\/li>\n<\/ol>\n\n<p>\ud83d\udcd6 <strong>Full API reference with every request, response and error code:<\/strong> <a href=\"https:\/\/github.com\/hammadev\/woocommerce-api-optimizer#readme\">GitHub documentation<\/a><\/p>\n\n<h4>At a Glance<\/h4>\n\n<p>Same endpoint, same credentials, one query parameter added:<\/p>\n\n<pre><code>GET \/wp-json\/wc\/v3\/products\/101?fields=id,name,price\n<\/code><\/pre>\n\n<ul>\n<li><strong>Fields returned per product:<\/strong> 66 by default \u2192 only the ones you ask for<\/li>\n<li><strong>Payload for one product:<\/strong> ~2.8 KB \u2192 ~130 B<\/li>\n<li><strong>Payload for a 20-product listing screen:<\/strong> ~56 KB \u2192 ~2.5 KB<\/li>\n<li><strong>New endpoints to learn:<\/strong> none \u2014 it's the same <code>wc\/v3<\/code> route<\/li>\n<\/ul>\n\n<h4>Why ShopMobi?<\/h4>\n\n<ul>\n<li><strong>One plugin instead of three.<\/strong> A headless WooCommerce frontend usually needs a JWT\/auth plugin, hand-written response-filtering code, and a separate Stripe integration. ShopMobi ships all of it as one tested package.<\/li>\n<li><strong>Built for SPA and mobile clients.<\/strong> Flutter, React Native, and native apps pay for every extra byte in load time, memory, and mobile data. A product screen that needs 4 fields shouldn't download 60+.<\/li>\n<li><strong>GraphQL-like control without leaving REST.<\/strong> Pick exactly the fields you want, per request \u2014 no schema, no query language, no extra server.<\/li>\n<li><strong>Auth, password reset, and Stripe included.<\/strong> Login, registration, profile updates, password reset, and Stripe <code>PaymentIntent<\/code> \/ <code>EphemeralKey<\/code> creation are ready to use, so you don't build and secure them yourself.<\/li>\n<\/ul>\n\n<h4>Field Filtering<\/h4>\n\n<p>Add an <strong>include list<\/strong> or an <strong>exclude list<\/strong> to any supported <code>wc\/v3<\/code> request, as a header or a query parameter:<\/p>\n\n<ul>\n<li><strong>Include only these fields:<\/strong> header <code>X-WC-Fields: id,name,price<\/code> or query <code>?fields=id,name,price<\/code><\/li>\n<li><strong>Exclude these fields:<\/strong> header <code>X-WC-Except: meta_data<\/code> or query <code>?except_fields=meta_data<\/code><\/li>\n<\/ul>\n\n<p>How it behaves:<\/p>\n\n<ul>\n<li>WooCommerce builds its normal response first \u2014 every hook, permission check, and sanitization rule still runs. ShopMobi only trims the <strong>top-level keys<\/strong> right before the response is sent.<\/li>\n<li>Collections (e.g. a product list) are trimmed item by item, so every item comes back in the same shape.<\/li>\n<li>If a header and a query parameter are both sent, the <strong>header wins<\/strong>. If an include and an exclude list are both sent, both apply.<\/li>\n<li>With an include list, only the listed fields come back \u2014 add <code>id<\/code> yourself if your app needs it.<\/li>\n<\/ul>\n\n<p>Example \u2014 only the fields a product list screen needs:<\/p>\n\n<pre><code>curl \"https:\/\/example.com\/wp-json\/wc\/v3\/products?fields=id,name,price,images\" \\\n  -u consumer_key:consumer_secret\n<\/code><\/pre>\n\n<p>Response (every product in the list is trimmed the same way):<\/p>\n\n<pre><code>[\n  {\n    \"id\": 101,\n    \"name\": \"Classic T-Shirt\",\n    \"price\": \"24.00\",\n    \"images\": [{ \"id\": 55, \"src\": \"https:\/\/example.com\/wp-content\/uploads\/tshirt.jpg\" }]\n  }\n]\n<\/code><\/pre>\n\n<p>Example \u2014 drop heavy fields from orders instead:<\/p>\n\n<pre><code>curl \"https:\/\/example.com\/wp-json\/wc\/v3\/orders?except_fields=meta_data,_links,tax_lines\" \\\n  -u consumer_key:consumer_secret\n<\/code><\/pre>\n\n<p><strong>Supported endpoints:<\/strong> products, product variations, orders, order refunds, and customers (list and single-item routes).<\/p>\n\n<p><strong>Variation enhancement:<\/strong> product responses return full variation objects instead of raw variation IDs \u2014 pricing, sale status, SKU, stock, attributes, and image URL \u2014 so a product page doesn't need one extra request per variation.<\/p>\n\n<h4>Custom Endpoints<\/h4>\n\n<p>All routes live under <code>https:\/\/your-site.com\/wp-json\/shopmobi\/v1<\/code>:<\/p>\n\n<ul>\n<li><code>POST \/users\/login<\/code> \u2014 log in with username and password (cookie-based, rate limited)<\/li>\n<li><code>POST \/users\/register<\/code> \u2014 create a customer account (rate limited)<\/li>\n<li><code>POST \/users\/update-profile<\/code> \u2014 update name and phone <em>(requires login)<\/em><\/li>\n<li><code>POST \/users\/reset-password\/generate<\/code> \u2014 email a password reset key<\/li>\n<li><code>POST \/users\/reset-password\/verify<\/code> \u2014 verify the key and set a new password<\/li>\n<li><code>GET \/general-settings<\/code> \u2014 store country, currency format, and active payment gateways<\/li>\n<li><code>GET \/store-location<\/code> \u2014 store address <em>(requires login)<\/em><\/li>\n<li><code>GET \/payment-gateways<\/code> \u2014 active payment gateways<\/li>\n<li><code>POST \/stripe-payment<\/code> \u2014 create a Stripe <code>PaymentIntent<\/code> + <code>EphemeralKey<\/code> for Stripe's mobile <code>PaymentSheet<\/code> <em>(requires login)<\/em><\/li>\n<\/ul>\n\n<p>Endpoints marked <em>requires login<\/em> need a valid WordPress session: cookie authentication with an <code>X-WP-Nonce<\/code> header, or <a href=\"https:\/\/make.wordpress.org\/core\/2020\/11\/05\/application-passwords-integration-guide\/\">Application Passwords<\/a> over HTTP Basic Auth. <code>\/users\/login<\/code> sets standard WordPress auth cookies; it does not return a bearer token.<\/p>\n\n<p>Request bodies, response examples, and error codes for every endpoint are in the <a href=\"https:\/\/github.com\/hammadev\/woocommerce-api-optimizer#custom-endpoints\">GitHub documentation<\/a>.<\/p>\n\n<h4>Third-Party Services<\/h4>\n\n<p>This plugin optionally integrates with <strong>Stripe<\/strong> (https:\/\/stripe.com) for payment processing. The Stripe integration is inactive until you provide API keys under <strong>WooCommerce &gt; API Optimizer<\/strong>.<\/p>\n\n<p>When the <code>\/shopmobi\/v1\/stripe-payment<\/code> endpoint is called, payment data (amount, currency, Stripe customer ID) is sent directly to Stripe's servers. No payment data passes through ShopMobi or any other third party.<\/p>\n\n<ul>\n<li>Stripe Privacy Policy: https:\/\/stripe.com\/privacy<\/li>\n<li>Stripe Terms of Service: https:\/\/stripe.com\/legal<\/li>\n<\/ul>\n\n<p>Your Stripe API keys are stored in your WordPress database and are never shared with the plugin author.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>This plugin stores data in your own WordPress database only:<\/p>\n\n<ul>\n<li><strong>Stripe customer IDs<\/strong> (<code>stripe_cust_id<\/code> user meta) \u2014 created when a user makes a Stripe payment, and shared only with Stripe to identify returning customers.<\/li>\n<li><strong>Password reset keys<\/strong> \u2014 handled entirely by WordPress core (<code>get_password_reset_key()<\/code> \/ <code>reset_password()<\/code>).<\/li>\n<\/ul>\n\n<p>The plugin does not track users, send analytics, or transmit personal data to ShopMobi or any third party, except payment data sent directly to Stripe when the Stripe endpoint is used.<\/p>\n\n<!--section=installation-->\n<h4>Standard Installation (Recommended)<\/h4>\n\n<ol>\n<li>Go to <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong> in your WordPress admin.<\/li>\n<li>Upload the plugin zip file and click <strong>Install Now<\/strong>.<\/li>\n<li>Click <strong>Activate Plugin<\/strong>.<\/li>\n<li>Optionally, go to <strong>WooCommerce &gt; API Optimizer<\/strong> to enter your Stripe API keys.<\/li>\n<\/ol>\n\n<h4>Installation from Source<\/h4>\n\n<ol>\n<li>Clone the repository and navigate to the plugin folder.<\/li>\n<li>Run: <code>composer install --no-dev --optimize-autoloader<\/code><\/li>\n<li>Copy the folder to <code>wp-content\/plugins\/<\/code> and activate from the Plugins screen.<\/li>\n<\/ol>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 5.8 or higher<\/li>\n<li>WooCommerce 6.0 or higher<\/li>\n<li>PHP 7.4 or higher<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"where%20is%20the%20full%20api%20documentation%3F\"><h3>Where is the full API documentation?<\/h3><\/dt>\n<dd><p>Every endpoint, with request bodies, response examples, and error codes, is documented on <a href=\"https:\/\/github.com\/hammadev\/woocommerce-api-optimizer#readme\">GitHub<\/a>.<\/p><\/dd>\n<dt id=\"does%20field%20filtering%20affect%20server%20performance%3F\"><h3>Does field filtering affect server performance?<\/h3><\/dt>\n<dd><p>The full WooCommerce response is built internally before filtering is applied, so server processing time is unchanged. The benefit is a smaller network payload for mobile and headless clients.<\/p><\/dd>\n<dt id=\"does%20this%20replace%20the%20woocommerce%20rest%20api%3F\"><h3>Does this replace the WooCommerce REST API?<\/h3><\/dt>\n<dd><p>No. This plugin adds a filtering layer on top of the standard WooCommerce REST API, and adds separate custom endpoints under <code>shopmobi\/v1<\/code> alongside it. All existing WooCommerce authentication, permissions, and hooks still apply.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20stop%20using%20field%20filtering%20%E2%80%94%20is%20there%20anything%20to%20migrate%3F\"><h3>What happens if I stop using field filtering \u2014 is there anything to migrate?<\/h3><\/dt>\n<dd><p>Nothing. Filtering only runs when a request includes <code>fields<\/code> \/ <code>X-WC-Fields<\/code> or <code>except_fields<\/code> \/ <code>X-WC-Except<\/code>. Stop sending those and every endpoint returns WooCommerce's normal, full response.<\/p><\/dd>\n<dt id=\"can%20i%20use%20both%20a%20header%20and%20a%20query%20parameter%20at%20the%20same%20time%3F\"><h3>Can I use both a header and a query parameter at the same time?<\/h3><\/dt>\n<dd><p>The header takes priority. If <code>X-WC-Fields<\/code> is present, the <code>fields<\/code> query parameter is ignored for that request \u2014 same rule for <code>X-WC-Except<\/code> vs <code>except_fields<\/code>.<\/p><\/dd>\n<dt id=\"is%20stripe%20required%3F\"><h3>Is Stripe required?<\/h3><\/dt>\n<dd><p>No. Stripe is completely optional. All other features \u2014 field filtering, auth endpoints, general settings \u2014 work without any Stripe configuration.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20woocommerce%20hpos%20%28high-performance%20order%20storage%29%3F\"><h3>Does this work with WooCommerce HPOS (High-Performance Order Storage)?<\/h3><\/dt>\n<dd><p>Yes. The plugin filters WooCommerce REST API responses and does not make direct database queries, so it is fully compatible with HPOS.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20compatible%20with%20caching%20plugins%3F\"><h3>Is the plugin compatible with caching plugins?<\/h3><\/dt>\n<dd><p>The field filtering works on REST API responses. If your caching plugin caches REST API responses, those cached responses will not be filtered. Disable REST API caching or configure it to vary by the <code>X-WC-Fields<\/code> \/ <code>X-WC-Except<\/code> headers.<\/p><\/dd>\n<dt id=\"where%20are%20stripe%20api%20keys%20stored%3F\"><h3>Where are Stripe API keys stored?<\/h3><\/dt>\n<dd><p>Stripe API keys are stored in the WordPress options table via the standard WordPress Settings API (<code>shopmobi_ao_stripe_secret_key<\/code>, <code>shopmobi_ao_stripe_public_key<\/code>). They are never logged, exposed in source code, or transmitted to any party other than Stripe.<\/p><\/dd>\n<dt id=\"does%20the%20plugin%20collect%20any%20data%3F\"><h3>Does the plugin collect any data?<\/h3><\/dt>\n<dd><p>The plugin stores the following data in your own WordPress database:<\/p>\n\n<ul>\n<li>Stripe customer IDs in user meta (<code>stripe_cust_id<\/code>) \u2014 only when Stripe is used<\/li>\n<li>Temporary password reset keys \u2014 handled entirely by WordPress core and invalidated automatically after use<\/li>\n<\/ul>\n\n<p>No data is sent to ShopMobi or any external service other than Stripe (when explicitly used).<\/p><\/dd>\n<dt id=\"can%20i%20use%20this%20plugin%20without%20woocommerce%3F\"><h3>Can I use this plugin without WooCommerce?<\/h3><\/dt>\n<dd><p>No. WooCommerce must be installed and active. If WooCommerce is not detected, the plugin will show an admin notice and will not register any hooks or endpoints.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<li>Field filtering via <code>X-WC-Fields<\/code> \/ <code>X-WC-Except<\/code> headers and <code>fields<\/code> \/ <code>except_fields<\/code> query parameters.<\/li>\n<li>Applies to products, orders, customers, and variation endpoints.<\/li>\n<li>Auth endpoints: login, register, update profile.<\/li>\n<li>Password reset endpoints: generate and verify.<\/li>\n<li>General settings endpoint: country, currency, store location, active gateways.<\/li>\n<li>Payment gateways endpoint.<\/li>\n<li>Stripe PaymentIntent endpoint with EphemeralKey support.<\/li>\n<li>Product variation response enhancer.<\/li>\n<li>Admin settings page under WooCommerce &gt; API Optimizer.<\/li>\n<\/ul>","raw_excerpt":"Is your WooCommerce API slowing your app? Cut REST payloads up to 90% with field filtering, plus ready-made auth, password reset &amp; Stripe endpoints.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/319035","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=319035"}],"author":[{"embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hammadev2"}],"wp:attachment":[{"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=319035"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=319035"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=319035"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=319035"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=319035"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/dsb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=319035"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}