ConnectWiz + WordPress

Live integration

Your WordPress site, chat-enabled and identity-aware

One plugin does two jobs: it places the chat widget on your WordPress site, and it mints signed sign-on tokens so a logged-in customer is recognized in the chat without re-registering — orders, history and all.

Widget embed, no code HMAC-signed SSO Works with members-only mode
WordPress × ConnectWiz
Logged-in customer detected
Signed SSO token minted
Chat opens — already recognized
2
Files in the plugin — small enough to audit over coffee
300 s
SSO token freshness window — a captured token dies in five minutes
1
Async script tag added — the two-stage loader your Core Web Vitals won’t notice
0
Theme files touched — styling stays in the ConnectWiz panel

E-commerce

What it does — precisely

Install, activate, done

The plugin drops the widget snippet site-wide — position, colors and behavior stay managed from the ConnectWiz panel, not from theme files.

SSO with real cryptography

Tokens are HMAC-signed server-side — a customer can’t forge an identity, and the widget can’t be tricked by an edited page.

One person, both worlds

The WordPress/WooCommerce account and the chat identity federate onto one contact — support sees the customer, not a stranger.

Members-only, safely

The widget’s "require login" mode pairs with SSO — and refuses to activate unless SSO is actually configured, so you can’t lock yourself out.

Under the hood

Small plugin, real cryptography

The token, precisely

Each SSO token is a signed pair — payload and HMAC-SHA256 signature keyed by your shared secret — carrying user ID, email, name and a timestamp. The server verifies in constant time and rejects anything older than 300 seconds.

One ID, two systems agreeing

The token’s subject is the WordPress user ID — which is also the WooCommerce customer ID. That single fact is why SSO identity and order matching land on the same contact instead of creating twins.

A footer-only footprint

The plugin adds one async script in the site footer with your widget key as data attributes — no render-blocking, no admin-side JavaScript, no queries added to your pages.

Three settings, one screen

Widget key, API base URL, SSO secret — the entire configuration surface. Everything visual and behavioral stays in the ConnectWiz panel, where it’s versioned and previewable.

Setup

How it connects

01

Install the plugin

Upload it to WordPress, activate, paste your widget key.

02

Enable SSO

Add the shared secret; the plugin signs tokens for logged-in users automatically.

03

Style from the panel

Colors, position and behavior stay in ConnectWiz — no theme surgery.

Better together

What it composes with

WooCommerce sync

Pair the store through the WooCommerce integration and the customer the plugin signs in arrives with orders, not just a name.

The widget itself

Everything on the live chat page — 52 languages, consent-first loading, in-chat apps — is what this plugin embeds.

Members-only chat

The widget’s require-login mode pairs with plugin SSO, and refuses to enable without it — so a checkbox can’t silence your site’s chat.

Security & guarantees

The boring guarantees

Forgery-proof identity

Identity claims are HMAC-signed server-side in PHP — a visitor editing the page can’t impersonate another customer, because the signature won’t verify.

Replay window: five minutes

Tokens carry issue time, not a long expiry — a leaked token is useless within minutes, and there’s nothing long-lived to steal.

One honest caveat

The shared secret lives in your WordPress options table, as WP plugins’ settings do — so treat wp-admin access as sensitive. We’d rather tell you where the secret sits than pretend it floats in the ether.

The honest fine print

Boundaries, stated

Not a content sync

The plugin carries the widget and identity — catalog and order sync is the WooCommerce integration’s job, and they compose cleanly.

Your origin, your rules

Web push for visitors still needs your own push app on your own domain — that’s how browsers work, and we say so.

No auto-update channel yet

The plugin installs as a zip today; a wordpress.org listing with managed updates is roadmap. Version bumps are announced, not silently pushed.

WordPress FAQ

Straight answers

More in the full FAQ, or ask us directly.

Two things: embeds the ConnectWiz chat widget on your WordPress site, and signs logged-in users into the chat with HMAC-signed SSO tokens so they arrive recognized — with their WooCommerce order history attached where the Woo integration is connected.

No — it inserts the same two-stage async loader the widget always uses: a tiny script after your content, the full app only on demand. Your Core Web Vitals stay yours.

Yes — the widget’s members-only mode hides the launcher from anonymous visitors, and it can only be enabled when SSO is configured, so a misconfiguration can’t silence your site’s chat.

Yes — the embed is a plain footer script, indifferent to Elementor, Divi or Gutenberg, and safe behind full-page caches: the widget bootstraps client-side and SSO tokens are minted per page view for logged-in users.

For anonymous visitors, nothing beyond the widget loading. For logged-in users with SSO enabled: user ID, email and display name, inside a signed token — no passwords, no roles, no browsing history.

Connected honestly beats connected loudly.

Every integration here is described by what it really does — direction, ownership and limits included.