Integrations

Connect products and commerce without surrendering licensing authority.

PipKey is intentionally independent of any one framework, payment provider or application stack.

WordPress / PHP

Keep service credentials on the server side, ideally in environment-backed configuration. Browser JavaScript must not receive the credential.

Desktop / mobile

Use the customer licence flow for activation and validation. Cache only bounded signed evidence that the product is designed to verify.

SaaS / backend services

Use scoped machine credentials for trusted service-to-service calls and keep product business logic in the application service.

WooCommerce

PipKey 1.0 contains a signed webhook-ingestion boundary. Fully automated order-to-licence processing remains separately controlled commercial work.

Square

PipKey 1.0 contains a signed Square event-ingestion boundary. Product mapping and licence automation must be explicitly reviewed and enabled.

Stripe

Stripe is part of the 1.1 commercial integration programme and should be treated as in development until an accepted release marks it available.

Commerce event rule

A verified payment or order event is evidence that something happened in a commerce system. It is not, by itself, permission to create, extend, downgrade or revoke a PipKey licence. Mapping and processing rules must translate that event into an auditable licensing transaction.

Webhook safety

  • Verify provider signatures using the exact raw request body where required.
  • Reject reused event identifiers when content differs.
  • Make processing idempotent.
  • Expect retries, duplicates and out-of-order events.
  • Never send raw cardholder data to PipKey.

Need an integration not listed here?

PipKey's generic architecture is intended to support additional platforms without making them licensing authorities. Contact PluginPip Ltd with the product, event model and trust boundary you need to integrate.