Integration guide
For your AI assistant to learn your offer, we need secure access to your site content. Choose your system below and follow the instructions.
WooCommerce (Shop)
How to generate a Consumer Key and Consumer Secret that can only access products — no orders, no customer data.
Why the extra steps? A WooCommerce key with "Read" permission sees everything its owner sees — including orders, customers and store settings. ZenTalk only needs products, so we create a dedicated user and add a small file that limits its key to reading products and the store currency.
Create a user for ZenTalk
In the WordPress admin select: Users → Add New. Username: zentalk-api (exactly like this — the file from the next step recognises it by this name). Email: any address you have access to. Role: Subscriber. Set a long, random password — nobody will log in to this account.
Install the security plugin
Download the ZenTalk plugin (ZIP file). In the WordPress admin select: Plugins → Add New → Upload Plugin, choose the downloaded file, click Install Now, then Activate.
Download plugin (ZIP)Prefer not to install a plugin? Copy the code below and save it as zentalk-api.php in the wp-content/mu-plugins/ folder on your store server (via FTP or your hosting file manager). If the mu-plugins folder does not exist, create it. WordPress loads files from this folder automatically — nothing to activate, and the file will show up under Plugins → Must-Use. Installed this way, it cannot be deactivated by accident.
<?php
/**
* Plugin Name: ZenTalk – read-only product access
* Plugin URI: https://zentalk.pl/instructions#woocommerce
* Description: Limits the "zentalk-api" user (WooCommerce key and Application Password) to reading products, the store currency and published pages and posts. Every other request returns 403.
* Author: ZenTalk
* Version: 1.0.0
* Date: 2026-07-01
*/
defined( 'ABSPATH' ) || exit;
$zentalk_is_api_user = static function () {
$user = wp_get_current_user();
return $user->exists() && 'zentalk-api' === $user->user_login;
};
// 1) Allow-list: the zentalk-api user may only GET products, the store currency and published content.
add_filter( 'rest_pre_dispatch', static function ( $result, $server, $request ) use ( $zentalk_is_api_user ) {
if ( ! $zentalk_is_api_user() ) {
return $result;
}
$route = untrailingslashit( $request->get_route() );
$allowed = 'GET' === $request->get_method() && (
preg_match( '#^/wc/v3/products(/\d+)?$#', $route )
|| '/wc/v3/settings/general/woocommerce_currency' === $route
|| preg_match( '#^/wp/v2/(pages|posts|categories|tags)(/\d+)?$#', $route )
);
if ( ! $allowed ) {
return new WP_Error( 'zentalk_forbidden', 'This account can only read products, pages and posts.', array( 'status' => 403 ) );
}
// Published content only, public fields only — whatever the caller asks for.
$request->set_param( 'context', 'view' );
if ( 0 === strpos( $route, '/wc/v3/products' ) ) {
$request->set_param( 'status', 'publish' );
}
return $result;
}, 10, 3 );
// 2) WooCommerce permission check: read only, published products and the currency setting only.
add_filter( 'woocommerce_rest_check_permissions', static function ( $permission, $context, $object_id, $object ) use ( $zentalk_is_api_user ) {
if ( ! $zentalk_is_api_user() ) {
return $permission;
}
if ( 'read' !== $context ) {
return false;
}
if ( 'settings' === $object ) {
return true;
}
return 'product' === $object && ( ! $object_id || 'publish' === get_post_status( $object_id ) );
}, 10, 4 );
- It only affects the zentalk-api user — nothing changes for you, your staff or your customers.
- It lets that user read published products and the store currency, plus published pages and posts (if you also connect WordPress) — nothing more.
- Every other request — orders, customers, coupons, reports, settings, WordPress users — returns a 403 "forbidden" error.
- It blocks all writes: this key cannot add, change or delete anything.
- It sends nothing anywhere, does not connect to ZenTalk servers and does not modify your store database.
- Deactivating or removing the plugin breaks nothing in your store — the ZenTalk key simply stops working.
No file access? Paste the code into the Code Snippets plugin (without the first <?php line) and set it to run everywhere.
Go to settings
Log in to the WordPress admin panel. In the left menu select: WooCommerce → Settings.
Find the REST API tab
Click the Advanced tab (top right), then select REST API in the submenu.
Add new key
Click Add key. Description: e.g. "ZenTalk Chat AI". User: zentalk-api (not your admin account). Permissions: Read.
Copy data
Click "Generate API key". You will see two strings: Consumer Key and Consumer Secret.
WordPress (Site / Blog)
How to create an Application Password for a dedicated user that can only read published pages and posts.
An Application Password is not your login password — it is a separate, API-only code you can revoke at any time. We create it for a dedicated user with the Subscriber role: it only sees what is already published on your site and cannot change or delete anything.
Create a user for ZenTalk
In the WordPress admin select: Users → Add New. Username: zentalk-api, email: any address you have access to, role: Subscriber. Set a long, random password — nobody will log in to this account. Already created this user in the WooCommerce guide? Skip this step — one user covers both the shop and the site.
Open the zentalk-api user profile
Go to Users → All Users, hover over zentalk-api and click Edit. Scroll to the bottom, to the Application Passwords section. Don't see it? You need WordPress 5.6 or newer, and some security plugins disable Application Passwords — in that case enable them in that plugin's settings.
Create an Application Password
In the New Application Password Name field enter ZenTalk and click Add New Application Password.
Copy the password
WordPress shows the password only once. Copy it in full — spaces don't matter, ZenTalk removes them.
Paste the details in ZenTalk
In the ZenTalk panel go to Settings → Integrations and add a WordPress integration. Enter zentalk-api in the Username field and paste the copied password into Application Password. You can revoke access at any time by revoking this password in the zentalk-api user profile.
Any store (product feed)
How to connect your catalog from any platform — Shoper, Shopify, PrestaShop, IdoSell, Wix or any other that generates a product feed for Google.
A feed is the simplest and safest option: ZenTalk only gets the product list you already share with Google Shopping or price comparison sites — no keys, no passwords, no access to your store admin. Feed and WooCommerce are mutually exclusive: enabling the feed disables the WooCommerce integration.
Generate a Google Merchant feed
In your store admin find the product export for Google Merchant Center / Google Shopping — usually in the integrations, marketing or price comparison module (in Shopify and Wix via a product feed app). You need a link to an XML file that the store keeps up to date.
Check the link
Open the link in a private browser window — it should show the XML with products right away, without logging in. The address must start with https://. A token in the address (e.g. ?key=…) is fine, but a login and password in the address (https://login:password@…) are not supported. Maximum file size: 200 MB.
Check what is in the feed
Every product must have g:id, g:title and g:link (the full product page address) — products without them are skipped. It should also have g:price or g:sale_price, g:availability, g:description, g:brand, g:image_link, g:mpn and g:product_type. Other fields (e.g. g:color, g:material, dimensions) reach the assistant as the product specification — the more details, the better the answers.
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:g="http://base.google.com/ns/1.0">
<channel>
<item>
<g:id>12345</g:id>
<g:title>Milano 3-seater sofa</g:title>
<g:link>https://shop.example/sofa-milano</g:link>
<g:description>Three-seater sofa bed, velvet, 228 cm wide.</g:description>
<g:price>799.00 EUR</g:price>
<g:sale_price>699.00 EUR</g:sale_price>
<g:availability>in stock</g:availability>
<g:brand>Milano</g:brand>
<g:mpn>MIL-3-GR</g:mpn>
<g:image_link>https://shop.example/img/sofa-milano.jpg</g:image_link>
<g:product_type>Furniture > Sofas</g:product_type>
<g:color>Grey</g:color>
<g:material>Velvet</g:material>
</item>
</channel>
</rss>
Paste the link in ZenTalk
In the ZenTalk panel go to Settings → Integrations. In the Product feed section paste the link into Feed URL, tick Enabled and click Save feed.
Run the sync
Run the first sync in Knowledge base → Sync products. After that ZenTalk fetches the feed automatically once a day — new products, prices and stock show up in the chat without any work on your side. The number of products depends on your plan (3k, 10k or 30k).
Only have a CSV file? Contact us — we will set up the column mapping (separator: semicolon, headers in the first row).
Shoper
How to generate an API key with limited permissions (read-only catalog). You will paste the key in the ZenTalk panel under Integrations.
Security best practice: use a dedicated user with WebAPI read-only access. ZenTalk does not need access to orders or customer data.
Create an admin group
Log in to the Shoper panel. Go to: Settings → General → Admin groups. Click Add group and name it e.g. "AI Integration".
Set WebAPI read-only
In the Permissions tab, uncheck everything. Check only WebAPI (API access). In the WebAPI section set READ (GET) only for: Products (Categories, Manufacturers, Attributes, Variants, Images), Information pages, Blog (Posts, Categories). Important: Orders and Customers must be UNCHECKED.
Add a user to the group
Go to: Settings → General → Users. Add a new user (e.g. api_zenTalk), set a password and assign them to the "AI Integration" group. Save.
Generate API key
In the Shoper panel go to WebAPI or Integrations (depending on version). Create a new API key/token for the user you created (or log in as that user and generate the key). Copy the displayed API key – this is the only value you need.
Paste the key in ZenTalk
In the ZenTalk panel (Integrations tab for the client) add a Shoper integration. In the "Shoper API Key" field paste the copied key. Save. From then on, sync will only fetch products, pages and blog.
Shopify
How to generate API keys with limited permissions (read-only catalog). You will paste the keys in the ZenTalk panel under Integrations.
Create a custom app
Log in to the Shopify admin. Go to: Settings → Apps and sales channels → Develop apps → Create an app. Name it e.g. "ZenTalk AI".
Configure API permissions
In the app configuration select Admin API. Set only read permissions, e.g.: read_products, read_online_store_pages (pages), read_content (blog). Do not enable orders or customers. Save.
Install app and get credentials
Install the app on your store (if required). In the API Keys / Tokens section copy the Client ID (or API key) and Client Secret (or API secret). In newer Shopify versions you may generate an Admin API access token – copy it.
Paste keys in ZenTalk
In the ZenTalk panel (Integrations tab) add a Shopify integration. Paste the copied API Key and API Secret into the corresponding fields. Save. Sync will only fetch products and content according to the permissions.
Wix
How to generate an API key. You will paste the key in the ZenTalk panel under Integrations.
Use an API key with read-only permissions for site content (products, blog, pages). ZenTalk does not need access to orders or user data.
Go to Developer Center
Log in to your Wix account. Go to developers.wix.com or in the site dashboard: Site Settings → Advanced → API. Open the developer dashboard / integrations.
Create an app or select site
Create a new app (or use an existing one). Select your site / store. In configuration set read-only permissions (e.g. read catalog, pages, blog).
Generate API key
In the API Keys / Credentials section generate a new API key (or copy an existing one). Save it securely – this is the only value you need for ZenTalk.
Paste key in ZenTalk
In the ZenTalk panel (Integrations tab for the client) add a Wix integration. In the "Wix API Key" field paste the copied key. Save. Sync will fetch content according to the key permissions.