Barcode Man for WooCommerce

Description

Barcode Man connects your WooCommerce store to a hosted workspace where you design and print custom product labels, address labels, and barcodes.

  • Design label templates with a visual editor (sizes, barcodes, product fields).
  • Print product labels populated from your WooCommerce products and variations.
  • Print address labels from your WooCommerce orders.
  • Generate and sync SKUs / barcodes back to your products.

The plugin connects your store to the Barcode Man service using WooCommerce’s
official authorization flow (/wc-auth/v1/authorize). WooCommerce creates and
manages the authorization credentials; the plugin does not keep its own copy.

This version is a connector: designing and printing happen in the Barcode Man
workspace at https://woocommerce.barcodeman.app, which opens in its own browser
tab. Nothing is embedded in your WordPress admin, and this package ships no
compiled application code. Connecting needs a Barcode Man account (email and
password), because the workspace belongs to the person signed in, not to the
site alone.

External services

This plugin connects your store to Barcode Man, a third-party label and barcode
service operated by Gookit (company website: https://gookit.co/barcodeman/), so
that your product and order data can be turned into printable labels and
barcodes. The service runs on its own domain, not on the company website:

  • API: https://prod-bcm-api.barcodeman.app
  • Workspace (WordPress.org build): https://woocommerce.barcodeman.app

What is sent, and when. This describes the WordPress.org connector; the Woo
Marketplace build of this plugin authenticates with a store session instead of
a Barcode Man account and has no sign-in step:

  • On connect: your store URL is sent to the Barcode Man API to open the
    connection, and your browser is sent to the workspace
    (https://woocommerce.barcodeman.app) to sign in. You create or sign in to a
    Barcode Man account there with an email address and password and accept the
    Terms of Service and Privacy Policy. That sign-in form talks directly to
    Barcode Man’s identity service, which is hosted on Supabase (an endpoint on
    supabase.co), so the email address and password you type are submitted to
    that service, which holds your email address for sign-in and support.
    After you approve the WooCommerce authorization, WooCommerce sends an API
    credential for your store directly to the Barcode Man API (server-to-server);
    the plugin itself never receives or stores that secret. Once you confirm the
    account and site, the Barcode Man API returns a Site Account ID plus a
    revocable plugin token, which the plugin stores to keep the connection.
    Supabase Terms of Service: https://supabase.com/terms
    Supabase Privacy Policy: https://supabase.com/privacy
  • While connected: opening the connector page sends the Site Account ID and
    plugin token to the Barcode Man API to check the connection status. The
    workspace runs in your browser and authenticates as the signed-in person;
    the site’s own token cannot open it.
  • While in use: the Barcode Man service reads your products, variations, and
    orders (and writes back generated SKUs / barcodes when you choose to) through
    the WooCommerce REST API in order to render and print labels.
  • While a connection is being made: this plugin publishes one value at
    /wp-json/barcode-man-wporg/v1/connect-proof — the SHA-256 of a random
    challenge the Barcode Man API just issued for this connection. The API reads
    it back from your site to confirm that a site administrator started the
    connection before it grants anything. It contains no personal or store data,
    and it is removed as soon as the connection finishes or is cancelled.
  • On disconnect: the stored Site Account ID and plugin token are sent to the
    Barcode Man API so it revokes workspace access to this site immediately. Both
    values stay on your site afterwards so you can reconnect the same account
    later; neither can open anything on its own.

This service is required for the plugin to function. By connecting you agree to
the Barcode Man Terms of Service (https://gookit.co/terms/) and Privacy
Policy (https://gookit.co/privacy/).

Paid billing depends on where this plugin build is distributed. The WooCommerce
Marketplace build uses the WooCommerce.com Billing API and does not send
Marketplace customers to Stripe. The WordPress.org build uses Stripe Checkout.

This plugin may also use these third-party services from within the app:

  • Stripe — if you choose to subscribe to a paid plan, the app requests a
    checkout link from the Barcode Man API and redirects your browser to Stripe
    Checkout (checkout.stripe.com) to complete payment. Only the data needed for
    checkout is sent by the Barcode Man API: a store-level Site Account ID in
    Stripe customer metadata, the Stripe customer ID, selected plan price, and
    success/cancel return URLs. Payment details you enter in Stripe Checkout are
    handled by Stripe. Product and order records are not sent for billing.
    Stripe Terms of Service: https://stripe.com/legal/consumer
    Stripe Privacy Policy: https://stripe.com/privacy
  • Google Fonts — the label editor loads font families from Google Fonts
    (fonts.googleapis.com and fonts.gstatic.com) when the connected app opens,
    so fonts are available for label designs. Your browser sends its IP address
    and request headers to Google when requesting the stylesheet and font files.
    Google Fonts Terms of Service: https://developers.google.com/fonts/faq
    Google Privacy Policy: https://policies.google.com/privacy

  • Formspree — when you submit the optional support form, your browser sends
    your name, email, message, any attachments you select, platform, app version,
    Site Account ID and any prefilled support topic to formspree.io so we can
    respond. Formspree also receives ordinary request information such as your
    IP address. Sending a support request is not required to use the plugin.
    Formspree Terms of Service: https://formspree.io/legal/terms-of-service/
    Formspree Privacy Policy: https://formspree.io/legal/privacy-policy/

  • Bytescale — when you upload an image for a label template, the Barcode Man
    API sends the image and a storage path containing the platform, Site Account
    ID and template ID to api.bytescale.com. Your browser requests the stored
    image from Bytescale’s CDN (upcdn.io) to display it; those requests include
    your IP address and browser request headers.
    Bytescale Terms of Service: https://www.bytescale.com/terms
    Bytescale Privacy Policy: https://www.bytescale.com/privacy

  • DigitalOcean Spaces — when you generate labels, the Barcode Man service
    stores the generated PDF in DigitalOcean Spaces. It contains whatever your
    template renders, including any product or customer/order information. Your
    browser requests the PDF from a digitaloceanspaces.com delivery URL when
    opening or downloading it, sending ordinary request information such as your
    IP address. No WordPress login or WooCommerce API credential is sent with
    that download request.
    DigitalOcean Terms of Service: https://www.digitalocean.com/legal/terms-of-service-agreement
    DigitalOcean Privacy Policy: https://www.digitalocean.com/legal/privacy-policy
  • Sentry — the Barcode Man application reports errors and performance data to
    Sentry (sentry.io) so failures can be diagnosed, and loads its session-replay
    module from browser.sentry-cdn.com. Replay records a playback of the screens
    you use: in production a sample of sessions, plus any session where an error
    occurs. That recording can include product names, the customer names and
    addresses shown on address labels, and images such as label previews and any
    logo you upload, along with your IP address and browser details.
    This happens in the hosted workspace, which is not part of this package: it
    ships no compiled application, so nothing is sent to Sentry from your
    WordPress admin.
    Sentry Terms of Service: https://sentry.io/terms/
    Sentry Privacy Policy: https://sentry.io/privacy/

Development

This package contains no compiled, minified or obfuscated code. Everything it
ships is the human-readable source that runs: the PHP
(barcode-man-for-woocommerce.php, includes/, uninstall.php) and one small
admin script (assets/js/bcm-connect-poll.js), which waits for the connection
to finish.

The Barcode Man workspace itself is a hosted service at
https://woocommerce.barcodeman.app. In this version it is not part of the
plugin, is not downloaded by it, and is not executed inside WordPress.

License

The plugin is distributed under GPLv2 or later; see LICENSE.txt. Builds that
also ship the compiled Barcode Man application keep their dependencies’ own
compatible licenses and copyright notices in THIRD-PARTY-NOTICES.txt and
licenses/.
These software licenses are separate from the terms for the hosted service.

Screenshots

Installation

  1. Upload the barcodeman-for-woocommerce folder to /wp-content/plugins/, or install the ZIP via Plugins > Add New > Upload Plugin.
  2. Activate the plugin through the ‘Plugins’ menu in WordPress.
  3. Go to WooCommerce > Barcode Man. If the site uses Plain permalinks, a WordPress administrator must switch to any other permalink structure first; the plugin offers a one-click “Post name” option to authorized administrators.
  4. Click “Connect this site to Barcode Man”. A WordPress administrator with WooCommerce permissions has to do this, because it decides which Barcode Man account controls this site’s data.
  5. Sign in (or create your Barcode Man account) at https://woocommerce.barcodeman.app, accept the Terms of Service and Privacy Policy, and approve the authorization request on the WooCommerce screen.
  6. Confirm the account and site shown, then return to WordPress. “Open workspace” takes you to Barcode Man whenever you need it.

FAQ

Does this plugin require an account or email sign-up?

Yes. The workspace is tied to a Barcode Man account, so connecting asks you to
sign in (or sign up) with an email address and password at
https://woocommerce.barcodeman.app and to
accept the Terms of Service and Privacy Policy. Your email address has to be
confirmed before a site can be connected, so the account can be recovered and
so we can reach the owner of a connection.

Does the plugin store my WooCommerce API keys on my site?

The plugin does not store its own copy. WooCommerce manages the API credential
on your site and sends it directly to the Barcode Man API during authorization.
The plugin stores a non-secret Site Account ID and a revocable plugin token.

What is the Site Account ID?

It is the stable, non-secret identifier for your store-level Barcode Man account.
You can view and copy it in Settings when contacting support. It is not a password
and cannot open a session without the separate plugin token.

Does the plugin add anything to my site’s REST API?

Only while a connection is in progress: one read-only route that returns the
hash of a one-time challenge, so the Barcode Man service can confirm the
connection was started by a site administrator here. It exposes no store or
personal data and disappears when the connection finishes.

What happens if I deactivate or delete the plugin?

Deactivating leaves your settings untouched. Deleting the WordPress.org version
keeps the Site Account ID and plugin credential so reinstalling can prove the
original connection. It clears local handshake and binding state and removes
Barcode Man’s per-plugin automatic-update selection. Deleting does not revoke
remote workspace access: use Disconnect before deleting if you want to revoke
it. The Woo Marketplace version removes its plugin token when deleted.

Why does the Woo Marketplace version require automatic updates?

Compatibility and security fixes for the Marketplace version are delivered by
Woo and installed by WordPress’s native updater. Barcode Man adds only itself to
the site’s per-plugin automatic-update list after an administrator explicitly
agrees. WordPress or hosting conditions can still prevent an individual update
from installing. You may turn the setting off from Plugins, but Barcode Man will
ask you to restore it before starting a new app session.

Does the plugin use an iframe?

No. This version does not display the application inside WordPress at all:
“Open workspace” opens Barcode Man at https://woocommerce.barcodeman.app in
its own browser tab.

Why does the plugin ask me to change Plain permalinks?

WooCommerce’s official store authorization flow and REST API require rewrite
routing that Plain permalinks do not provide. A WordPress administrator can use
the one-click “Post name” option shown by Barcode Man, or select any non-Plain
structure under Settings > Permalinks. Shop managers who cannot change this
site-wide setting will see instructions to contact an administrator.

Does deleting the plugin cancel my subscription or delete my service account?

No. Manage or cancel your paid plan before deleting the plugin. Deleting local
plugin files does not cancel billing, revoke the current WooCommerce
authorization, or delete data held by the Barcode Man service.
Paid plans on this version are billed through Stripe; cancel yours in Barcode
Man.
You can revoke the authorization under
WooCommerce > Settings > Advanced > REST API. Contact hi@gookit.co to request
service-account or personal-data deletion.

Reviews

7 ตุลาคม 2021
I need an app for helping me do customized layout, and it did great job. not only include a label editor that support drag and drop but also have some common label to help me figure out how to use it. the installation is tedious, we hope you can improve it. the rest of all is good.
Read all 1 review

Contributors & Developers

“Barcode Man for WooCommerce” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.1.0

  • First WordPress.org release of the connector, replacing the 2022 plugin (1.0.1). Includes every change listed under 1.0.2 and 1.0.0 below.
  • The connection screen names the workspace address you sign in at.
  • Tested with WooCommerce 11.1.

1.0.2

  • The WordPress.org release is published under the existing listing again: same plugin directory and main file as 1.0.1, so an installed copy updates in place instead of being deactivated.
  • The WordPress.org and Woo Marketplace releases are now separate installs with separate stored settings, so holding both on one site no longer lets either one’s removal disconnect the other.

1.0.0

  • The WordPress.org release is a connector: you sign in to a Barcode Man account, and designing and printing happen in the hosted workspace at https://woocommerce.barcodeman.app, which opens in its own browser tab. Nothing is embedded in your WordPress admin and this package ships no compiled application.
  • The Woo Marketplace release keeps the application embedded in wp-admin, and still ships the readable frontend source and third-party license texts needed to rebuild it independently.
  • Updated service policy links and external-service disclosure; added the GPL license text to every package.
  • First WordPress.org submission: dev-only code stripped from release builds, translatable strings, i18n text domain setup, connecting-screen poller moved to a properly enqueued asset, and clear recovery for unsupported Plain or stale permalink routing.
  • Added isolated Woo Marketplace and WordPress.org build channels and native automatic-update onboarding for Woo-deployed artifacts.

0.0.1

  • Initial release.