n8n and WordPress: posts and WooCommerce orders

n8n talks to WordPress through WordPress’s own REST API. That allows two things: n8n can create or update posts on your site, and WooCommerce can notify n8n when an order comes in. The site can be on a hosting plan and n8n on a VPS: they are different machines, and that is fine.

The credentials, and why there are two

For Credential Where it comes from
Creating and editing posts User name and application password. Generated in a WordPress user’s profile. Works only on sites with HTTPS.
Reading and managing the shop The WooCommerce REST API key and secret. Generated in the advanced WooCommerce settings, choosing whether they only read or also write.

The exact names of the screens vary between WordPress and WooCommerce versions; both are described in their own documentation. What matters is the rule: one credential per purpose, with the fewest powers.

Connecting the two

1 Confirm the site answers on HTTPS and that pretty permalinks are not set to plain. Without them the REST API returns 404. See WordPress permalinks and the 404 that follows.
2 Create a user just for n8n, with the lowest role that will do. See adding a WordPress user, and which role to give them.
3 Generate the application password for that user and save it at once: it is shown only once. You can revoke it without changing the account password.
4 Create the credential in n8n with the site address, the user name and the application password. On the first test, create the post as a draft, not published.
5 For the shop, generate the WooCommerce REST API key and secret and create the credential. To receive orders, use the n8n WooCommerce trigger, or create a webhook in the shop pointing at the production address of a Webhook node. See n8n webhooks.
6 Pick the right event. A created order is not paid yet. If the workflow notifies the customer or handles deliveries, filter on the “paid” or “processing” status.

When it fails

Error Likely cause What to do
401 unauthorised Wrong user name or application password, or the authentication header being stripped before it reaches WordPress. Generate a new application password and test. If it persists, look at your server or a security plugin.
403 forbidden A security plugin or the firewall blocks your VPS IP. See why your IP gets blocked.
404 no route Permalinks on plain, or the site address mistyped. Save the permalinks again; check the address.
The shop stopped notifying WooCommerce disables a webhook that fails several times in a row. Fix the workflow, then re-enable the webhook in the shop.
Shop e-mails do not arrive An e-mail problem, not an n8n one. See WooCommerce e-mails not arriving.
The application password carries the powers of its user. If that user is an administrator, whoever steals it controls the site. Always use a user with the minimum role, and a shop credential that only reads if the workflow only reads.
Rehearse on a test site before pointing the workflow at the live one. See a test site before touching what is live.

Do not have the WordPress site or shop set up yet?

See WordPress hosting

SEE ALSO

WordPress hosting

Getting paid: connecting a payment method to WooCommerce

n8n webhooks: test URL and production URL

Securing n8n: access, credentials and exposed webhooks

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up. from 321,75 MT/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?