counterhand MCP for WooCommerce

How it works

Two ways in, and exactly what happens in each.

Both reach the same tools with the same safeguards. They differ in one thing: whether an outside app is holding a key, or whether you are simply signed in to your own shop.

Way one

Your own AI app, connected to the shop.

You keep working in Claude or ChatGPT, and your shop becomes something they can reach — with permissions you grant once and can withdraw whenever you like.

Use this when you already live in an AI app and want your shop available in the same conversation as everything else.

  1. 01

    You, in your shop

    Switch on the areas you are willing to expose

    In your shop admin, open Counterhand MCP → Settings and tick the areas you are willing to expose at all. Reading and changing are separate ticks for every area, so “may look at orders” never implies “may edit them”.

    Out of the box only three areas are readable — products, orders and reports — and nothing is writable. The other thirteen areas, every write, and any area a future update adds all start switched off.

  2. 02

    You, in the AI app

    Paste one address

    Copy the one address from the Connect AI apps tab and paste it into your AI app. There is no key to generate and nothing to paste back.

    https://yourshop.com/mcp

    That tab also checks the address from the outside and tells you if your server is blocking it before you try the app.

  3. 03

    The app, automatically

    It asks your shop what is possible

    The app reads two small documents your shop publishes: one saying which permissions exist, one saying where to ask for them. This is the standard handshake — the app needs no configuration for your shop specifically.

    Your shop only advertises the areas you switched on. An app can still ask for one that is off, but on the permission screen that row is greyed out with the reason — it cannot be granted until you switch the area on.

  4. 04

    You, in your browser

    You approve exactly what it may do

    Your browser opens a permission screen on your own shop — not on the AI provider’s site. You sign in to WordPress if you are not already, and you see the app’s verified name, every area it asked for, and every area you have switched off.

    Untick anything you would rather not grant. What the app asked for and your shop allows starts ticked — except payment methods, store settings and maintenance, which always take a deliberate click. Anything the app asked for but cannot have is greyed out, with the reason on the row.

    If the app can change anything at all with what is ticked, the screen says so above the buttons. And an app that names no permissions is offered the read-only areas only, never a blank cheque.

    Only someone who can manage WooCommerce may approve a connection.

  5. 05

    Your shop, automatically

    The app gets its own limited key

    On approval your shop issues that one app its own key, in the background. It carries exactly the permissions you ticked — no more, and it cannot widen later.

    • Valid for 30 days, then the app asks again
    • Limited to 60 requests a minute by default
    • Revocable at any moment from the Connections tab
  6. 06

    You, from then on

    Just ask

    Now you just talk to your shop in the app you already use. Ask what sold last week, look up an order, fix a price. The assistant sees only the tools your ticks allowed.

    Every call is written to the action log in your admin: which app, which tool, and whether it worked.

Way two

The chat built into your shop admin.

Nothing to connect and no permission screen — a chat tab next to Orders and Products, using the same tools.

Use this when you would rather not connect an outside app at all, or your shop is not reachable from the internet.

  1. 01

    You, in your shop

    Open the Chat tab

    Open Counterhand MCP → Chat in your shop admin. There is nothing to connect and no permission screen: you are already signed in to WordPress, so the chat can reach exactly what your own account can and nothing more.

  2. 02

    You, once

    Choose which model does the thinking

    Pick where the thinking happens. Either let WordPress manage the connection for you — one connection the whole site shares, with no key for this plugin to hold — or paste your own key.

    • Anthropic (Claude)
    • ChatGPT (OpenAI)
    • Gemini (Google)
    • Ollama, running on your own server — nothing leaves the building
    • Any other endpoint that speaks the same format

    When WordPress manages it, the key stays with WordPress and this plugin never sees or stores it.

  3. 03

    You, once

    Pick the areas the chat may use

    Tick which areas this chat may use. It is a separate choice from what you grant external apps, so the chat can be broader or narrower as you prefer. It starts with four everyday areas — products, orders, customers and reports, about thirty tools.

    A Claude model can carry the whole catalogue, because it searches for the tool it needs instead of being handed all of them. Other models hold up to sixty tools in one message, and the chat tells you exactly what to untick if you go past that.

    The picker shows where your Settings overrule a tick, with a link to change it — a box you tick here can never exceed what Settings allows.

  4. 04

    You, from then on

    Ask, in the same window

    Type the question. The model runs on your server, calls the same tools an external app would, and answers in the same window — showing you which tools it used along the way.

    Identical safeguards apply: new products are drafts, sensitive changes need your explicit confirmation, and everything lands in the action log.

Side by side

Which one you want.

The two ways to use Counterhand, compared on the points where they differ.
Point Your own AI app Chat in the admin
Where you work In Claude, ChatGPT or your editor In your shop admin
Setup Paste one address, approve a permission screen Choose a model, tick the areas
What limits it The permissions you ticked, for that app alone What your own WordPress account can do
Needs a public shop Yes for Claude and ChatGPT; no for editor tools No — works on a local shop
Who pays for the model Your existing AI subscription Your own API key, or WordPress’ connection
Withdrawing access Revoke that connection; others keep working Untick the areas, or switch the chat off

You do not have to choose — both can be on at once, and many shops run the admin chat daily while keeping one app connected for longer jobs.

Still deciding?

Install it and connect it to your own shop — that answers more than any page can. It is free, and nothing is published or changed until you say so.