Description
Condixia – REST Gateway provides authenticated and controlled REST access to WordPress content and selected WooCommerce data for external applications.
It is designed for developers building applications such as Laravel dashboards, headless frontends, mobile applications, internal tools, reporting systems, and SaaS integrations that use WordPress as a backend.
Condixia uses its own API client and credential system. External applications do not need WordPress user passwords, login cookies, Application Passwords, WooCommerce consumer keys, JWT plugins, or OAuth plugins.
Core Features
- Secure Condixia API clients and Bearer credentials.
- API credentials are stored as hashes rather than reusable plaintext secrets.
- API secrets are displayed only when initially created.
- Per-client scopes and permissions.
- Credential expiration, disabling, and revocation.
- Versioned REST namespace using
condixia/v1. - Read access to posts, pages, and supported public custom post types.
- Explicitly controlled create and update access for supported WordPress content.
- Write operations are disabled by default per resource.
- Read-only WooCommerce product access.
- Read-only WooCommerce order access.
- WooCommerce HPOS-compatible order access using supported WooCommerce APIs.
- Pagination, searching, filtering, sorting, and field selection where supported.
- Basic per-client rate protection.
- Resource schemas that prevent unrestricted field and metadata exposure.
- Endpoints documentation inside WordPress Admin.
- API client management inside WordPress Admin.
- No DELETE operations in the Free edition.
Security Model
Condixia separates authentication from authorization.
Authentication determines which Condixia API Client is making the request.
Authorization determines which resources and operations that client may access.
Successfully authenticating does not automatically grant unrestricted access.
Resources expose explicitly defined fields rather than raw WordPress or WooCommerce objects. Arbitrary post metadata, authentication data, session information, API secrets, and other protected internal values are not exposed by default.
WordPress content writes use supported WordPress APIs. WooCommerce order and product access uses supported WooCommerce APIs.
Authentication
External applications authenticate using an HTTP Bearer credential:
Authorization: Bearer cxi_v1_<client-id>.<secret>
The plaintext secret is shown only when the API client is created.
Store API credentials securely in your external application.
Production API requests should use HTTPS.
Example Request
Retrieve WordPress posts:
GET /wp-json/condixia/v1/resources/posts
Example cURL request:
curl -H "Authorization: Bearer <your-api-key>" "https://example.com/wp-json/condixia/v1/resources/posts"
Retrieve a specific post:
GET /wp-json/condixia/v1/resources/posts/123
Retrieve WooCommerce products:
GET /wp-json/condixia/v1/resources/products
Retrieve WooCommerce orders:
GET /wp-json/condixia/v1/resources/orders
Available resources depend on the active WordPress post types, installed plugins, WooCommerce availability, resource configuration, and the API client’s assigned scopes.
Third-Party Libraries
Condixia – REST Gateway includes Select2 for searchable multi-select controls in the WordPress administration interface.
Select2
Version: 4.1.0
License: MIT
Project: https://select2.org/
Source: https://github.com/select2/select2
The Select2 license is included with the bundled library.
Installation
- Upload the
condixia-wp-rest-gatewaydirectory to/wp-content/plugins/, or install the plugin through the WordPress Plugins screen. - Activate Condixia – REST Gateway.
- Open Condixia REST > API Keys.
- Create an API client.
- Assign only the scopes required by the external application.
- Copy the generated API credential immediately. It cannot be retrieved again.
- Open Condixia REST > Endpoints to inspect available resources and routes.
- If WordPress content writes are required, explicitly enable the appropriate resources under Condixia REST > Settings.
FAQ
-
Does Condixia require a WordPress user account for API authentication?
-
No. Condixia API clients authenticate independently from WordPress user accounts.
-
Does it use WordPress Application Passwords?
-
No. Condixia has its own API credential system.
-
Does it require JWT or OAuth?
-
No. The Free edition uses secure opaque Bearer credentials.
-
Are API secrets stored in plaintext?
-
No. Reusable API secrets are stored as secure hashes. The original credential is displayed only when it is created.
-
Can an API client access everything after authentication?
-
No. Authentication and authorization are separate. Each client must have the required scope for the requested resource or operation.
-
Does Condixia expose all post metadata?
-
No. Resources use explicit schemas and do not expose arbitrary metadata by default.
-
Can external applications create and update WordPress content?
-
Yes, for supported WordPress content resources when write access has been explicitly enabled and the API client has the required create or update scope.
-
Are write operations enabled automatically?
-
No. WordPress resource writes are disabled by default.
-
Can the API delete WordPress content?
-
No. DELETE operations are not included in the initial Free edition.
-
Does Condixia support WooCommerce?
-
Yes. When WooCommerce is active, Condixia provides read-only product and order resources.
-
Can the API modify WooCommerce orders?
-
No. WooCommerce access in the Free edition is read-only.
-
Does it support WooCommerce HPOS?
-
Yes. WooCommerce orders are accessed using WooCommerce CRUD and query APIs rather than assuming orders are stored as WordPress posts.
-
Does Condixia send usage information to Condixia?
-
No hidden telemetry is included.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Condixia – REST Gateway” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Condixia – REST Gateway” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
0.1.0
- Initial development release.
- Added Condixia API client authentication.
- Added hashed API credential storage.
- Added API scopes and authorization.
- Added WordPress resource discovery.
- Added authenticated REST resource reads.
- Added controlled WordPress create and update operations.
- Added read-only WooCommerce product and order resources.
- Added WooCommerce HPOS compatibility.
- Added basic per-client rate protection.
- Added Dashboard, Endpoints, API Keys, and Settings administration screens.
- Added public resource and provider extension contracts.




