Integrations
Connect products and commerce without surrendering licensing authority.
PipKey is intentionally independent of any one framework, payment provider or application stack.
WordPress / PHP
Keep service credentials on the server side, ideally in environment-backed configuration. Browser JavaScript must not receive the credential.
Desktop / mobile
Use the customer licence flow for activation and validation. Cache only bounded signed evidence that the product is designed to verify.
SaaS / backend services
Use scoped machine credentials for trusted service-to-service calls and keep product business logic in the application service.
WooCommerce
PipKey 1.0 contains a signed webhook-ingestion boundary. Fully automated order-to-licence processing remains separately controlled commercial work.
Square
PipKey 1.0 contains a signed Square event-ingestion boundary. Product mapping and licence automation must be explicitly reviewed and enabled.
Stripe
Stripe is part of the 1.1 commercial integration programme and should be treated as in development until an accepted release marks it available.
Commerce event rule
A verified payment or order event is evidence that something happened in a commerce system. It is not, by itself, permission to create, extend, downgrade or revoke a PipKey licence. Mapping and processing rules must translate that event into an auditable licensing transaction.
Webhook safety
- Verify provider signatures using the exact raw request body where required.
- Reject reused event identifiers when content differs.
- Make processing idempotent.
- Expect retries, duplicates and out-of-order events.
- Never send raw cardholder data to PipKey.
Need an integration not listed here?
PipKey's generic architecture is intended to support additional platforms without making them licensing authorities. Contact PluginPip Ltd with the product, event model and trust boundary you need to integrate.