Description
At a glance
AVA Pay for WooCommerce v0.4.1 — free WordPress plugin download. Key facts: updated September 29, 2026 · requires WordPress 6.5+ & PHP 7.4+.
AI agents are already shopping your store. ChatGPT browses product pages, agentic checkouts are rolling out across the ecosystem. AVA Pay tells you which agents to trust, lets you set the rules, and records every verification and attributed order so you can see the traffic when reporting lands.
This plugin connects your WooCommerce store to the AVA Pay verification API, which cryptographically verifies agent traffic across protocols (Visa Trusted Agent Protocol, IETF Web Bot Auth, Google AP2) through a single endpoint.
What it does
- Adds a verify endpoint (
/wp-json/ava-pay/v1/verify-agent) that proxies signed agent requests to the AVA Pay API. Signatures are verified server-side against the agent platforms’ published keys. - Applies YOUR policy: accept/reject verified agents, per-platform allow/challenge/block rules, discount caps, and spend limits, kept as a portable JSON policy document.
- Optionally mints a single-use, expiring WooCommerce coupon for verified agents.
- Shows signed AI agent visits to your store. When an AI agent loads a page with its requests signed (ChatGPT’s agent does; most crawlers do not), the plugin checks the signature with the AVA Pay API after the page has been sent and lists the result under WooCommerce, Agent visits: counts for the last 7 and 30 days by agent platform and outcome, and the last 50 visits. This only observes: a page view is never blocked, redirected or given a coupon because of it. You can turn it off in the settings.
- Records every verification and every attributed order in local database tables. (Agent page visits are shown as above; a traffic and revenue dashboard for the verify endpoint and orders is planned, and that data is not displayed yet.)
Trust model, honestly stated
- Verification proves agent identity and request integrity. A discount is only granted beyond your identity-only tier when the request carries a buyer mandate.
- Everything fails closed: if the verification API is unreachable, agents are not admitted (and the outcome is recorded as an error).
- We do not claim to have blocked an agent we never managed to check. When the verification API cannot reach an agent’s trust root, the request is still not admitted, but it is recorded as
unverifiablerather than as a rejection, and the storefront response saysverification_unavailableinstead ofagent_blocked. - The plugin never blocks human shoppers. A failed agent verification means “no discount, proceed normally.”
External services
This plugin connects to the AVA Pay verification API, operated by Agentic Verification Architecture LLC, to check whether an AI agent’s signed request is genuine. Your store cannot verify agent signatures on its own; this API does the cryptographic check against the agent platforms’ published keys.
- Service: AVA Pay verification API. The plugin sends
POST https://pay.avalayer.com/verify. The base URL is the “AVA Pay API URL” setting (defaulthttps://pay.avalayer.com) and can also be changed with theava_pay_api_urlfilter. - When data is sent: in two cases. (1) When a request is POSTed to the plugin’s verify endpoint,
/wp-json/ava-pay/v1/verify-agent, and passes the local rate limit. That endpoint is how signed agent requests reach the plugin, either directly from the agent or from the storefront script on a page view that carries agent signature parameters. (2) When a front-end page request (GET or HEAD) carries agent signature headers (SignatureandSignature-Input), the “Verify signed AI agent page visits” setting is on, and the visit is not skipped (checks run one at a time, within a per-agent and per-site budget, and an agent whose last check could not complete is paused for 10 minutes); this happens after the page has been sent. The plugin forwards each such request, with only the headers listed below, and lets the API decide; a request without valid signature material is rejected there. Nothing is sent for page views without agent signature headers, in the admin, or during checkout. - What is sent: the incoming request’s HTTP method; the URL, which for the verify endpoint is its canonical URL built from your site’s own address rather than from the incoming request, and for a page visit is the page’s URL as the agent requested it (the
Hostheader it sent plus the path and query string); only the request headers verification needs, which areSignature,Signature-InputandSignature-Agent, every header the agent’s signature names as covered, the protocol headers the verifier reads by name (X-Ava-Mandate,X-Ava-Discount-Hint, the AP2 mandate headers,Content-Digest, andContent-Typewhen there is a body), andHost, replaced by your site’s own host on the verify endpoint and sent as received for a page visit; and the request body, if there is one (a page visit has none). Every other header is dropped before the request leaves your site, includingX-Forwarded-ForandUser-Agent(unless the agent’s signature covers it).Cookie,Authorization,Proxy-AuthorizationandX-WP-Nonceare never forwarded, even when the agent’s signature covers them. - What is not sent: no customer, order, or session data. No cookies, no logged-in user information, no cart contents, no visitor IP address, and no store settings or policy.
Terms of service: https://avalayer.com/terms
Privacy policy: https://avalayer.com/privacy
Frequently asked questions
What is AVA Pay for WooCommerce?
AVA Pay for WooCommerce is a free WordPress plugin available under the GPL license. The current version is 0.4.1.
Is AVA Pay for WooCommerce free to download?
Yes — AVA Pay for WooCommerce 0.4.1 is a free GPL download with no hidden fees, no account needed, and no feature locked behind a paywall in this package.
How do I install AVA Pay for WooCommerce 0.4.1?
Download the ZIP file from this page, then in your WordPress dashboard go to Plugins → Add New → Upload Plugin, choose the file, click Install Now, then Activate. The plugin works immediately after activation — no license key or extra setup is required for the core features.
What are the requirements for AVA Pay for WooCommerce?
AVA Pay for WooCommerce 0.4.1 requires WordPress 6.5 or higher and PHP 7.4 or higher. Most modern WordPress hosts already meet these versions. Running older versions may cause features to break, so update WordPress and PHP first if your site is behind.
When was AVA Pay for WooCommerce last updated?
Version 0.4.1 was last updated on September 29, 2026. This page is refreshed automatically, so the download here always matches the newest version we have verified.
Is the AVA Pay for WooCommerce download safe?
The file is sourced directly from the official WordPress.org repository — the same file the developer published. It is served unmodified, so what you install here is byte-identical to the official release.
Technical details
| Version | 0.4.1 |
|---|---|
| Last updated | September 29, 2026 |
| Requires WordPress | 6.5 or higher |
| Requires PHP | 7.4 or higher |
| Author | Agentic Verification Architecture |
| Tags | agentic-commerce, ai-agents, bot-verification, coupons, security |
Download AVA Pay for WooCommerce
Download AVA Pay for WooCommerce WP PluginNote: if the download does not start, disable your ad blocker and try again.