Skip to content
WooRescueHQ

WooCommerce / Integrations

WooCommerce integration problems: REST API, webhooks and external systems

Integrations fail at the edges: authentication, network, timeouts, retries and data mapping. The challenge is that each side only sees half of the conversation — so the diagnosis starts by putting both halves together.

Short answer

For the REST API, read the exact error code in the response: woocommerce_rest_cannot_view or a 401 points to authentication or key permissions, 403 to a security layer, 500 to a PHP error on the store. For webhooks, open the webhook's delivery log in WooCommerce: response codes, timeouts and repeated failures. WooCommerce disables a webhook after repeated failed deliveries.

Specific problems

Common integration failures

Put both halves of the conversation together

An integration problem usually looks different from each side. The ERP says "the store returned an error"; the store's logs show nothing. Or the store says "webhook delivered", while the receiving system says it never processed it. The diagnosis lines up both sides for the same order or request, by timestamp and identifier.

Symptom Look at
API client gets 401/403 API key permissions, authentication headers reaching PHP, security rules
API client gets 500 PHP and fatal-errors logs on the store at that timestamp
Webhook "not received" WooCommerce delivery log for the webhook, response code, duration
Data arrives twice Retries without idempotency, duplicated webhooks, multiple sync jobs
Checkout slow or failing Synchronous external calls during the checkout request

Build integrations that can be debugged

Integrations that are easy to diagnose share a few traits: every request is logged with an identifier, failures are retried with limits, operations are idempotent so retries do not duplicate data, and heavy or slow work runs in the background instead of inside a customer's request.

Frequently asked questions

Why does the WooCommerce REST API return 401?

Common causes are wrong or revoked API keys, keys without read or write permission, authentication headers stripped by the server or a proxy, and sending basic authentication over plain HTTP. The response body's error code narrows it down.

Why was my WooCommerce webhook disabled?

WooCommerce disables a webhook after a number of consecutive failed deliveries — responses outside the 2xx range or timeouts. Fix the receiving endpoint, then re-enable the webhook. The delivery log shows each failed attempt.

How do I verify a WooCommerce webhook is genuine?

Each delivery includes an X-WC-Webhook-Signature header: a base64-encoded HMAC-SHA256 of the request body, using the webhook's secret. Compute it on the receiving side and compare.

$ describe the problem

Have a WooCommerce problem?Request a diagnosis.

Tell us what is failing, what changed recently and the business impact. We review every request and recommend the appropriate next step.

Request a diagnosis See services and prices

Never send passwords, API keys or card data through the form.

Diagnosis from€299

Request a diagnosis