message.comDevelopers

WordPress and WooCommerce plugin

Install the plugin from your Message workspace and explicitly approve knowledge access.

Create an install kit

Open https://app.message.com/settings/integrations/wordpress. Generate an install kit and save its one-time token and plugin ZIP. The token expires after 24 hours. Use a separate kit for each site.

Install and connect

In WordPress, upload and activate the ZIP. Open the message.com menu, paste the install token and choose Connect. Return to Message and confirm the site appears under Connected sites. This is a token-based connection, not a promised WordPress.org directory or OAuth installation.

Approve knowledge sources

In the plugin Overview, approve knowledge syncing and choose public content. Review source status and imported knowledge before relying on AI answers. The AI does not receive unrestricted database or administrator access.

Enable verified order lookup separately

WooCommerce order lookup is separate from public knowledge. Enable the offered verification flow and test access with the correct customer details and with incorrect details. Do not treat a known email address as permission to disclose a private order.

Widget and other plugins

The plugin loads the widget through the connected site embed identifier. Configure its appearance in Message Chat settings. Verify and Marketing SMS have separate plugin packages at https://app.message.com/settings/integrations/wordpress-tools. The old message-widget shortcode and message_event hook examples are not public plugin contracts.

Verify the published installation

Test the published page in a separate browser session. Confirm widget.js loads, the launcher opens, a visitor message reaches Inbox and an agent reply returns. Test with your site’s actual content security policy, consent controls and mobile layout.

The script connects to its own origin by default. With the standard snippet, allow the relevant script and HTTPS/WSS requests to app.message.com. Check image, media and injected-style requirements separately. Do not put an agent JWT or integration secret in the page.