Install and connect
Install Agoo for WordPress, connect it with your publishable key, and optionally set up the webhook receiver.
This is designed and scheduled but not built yet. We document it now so you can plan your integration.
Setting up takes two parts. The first is all most sites need: install the plugin and add a publishable key. The second, optional, part receives Agoo events in WordPress.
These steps will work once the plugin is published on WordPress.org.
Install the plugin
- In your WordPress admin, go to Plugins → Add New Plugin.
- Search for Agoo. Check that the author is Ardent.
- Select Install Now, then Activate.
You need the install_plugins capability (Administrators have it). On a multisite network, a Super Admin installs it; see multisite.
Connect with your publishable key
Create a publishable key in Agoo
An Agoo admin opens Console → Developers → API keys and creates a publishable key. Create a test key (agoo_pk_test_…) first, so you can try everything without sending messages to anyone, then a live key (agoo_pk_live_…) when you're ready.
A publishable key is safe to show in web pages. It can only read your public booking types and the visitor types open for pre-registration, and create bookings and pre-registrations.
Paste it into WordPress
Go to Settings → Agoo, paste the key into Publishable key and select Save changes. The plugin checks the key with Agoo and shows the organisation it belongs to and whether it's a test or live key.
Add a block
Edit a page, add the Agoo booking or Agoo pre-registration block, and choose the booking type or site from the list. See blocks and shortcodes.
That's all you need for booking and pre-registration. Go live by replacing the test key with your live key; your blocks keep working.
Optional: receive Agoo events
Set this up if you want WordPress to do something when things happen in Agoo, for example post to Slack when a visitor checks in. It needs the Growth plan or above, and your site must use HTTPS.
Note your receiver URL
Settings → Agoo → Webhooks shows your site's receiver URL:
https://www.example.org/wp-json/agoo/v1/webhooksIf your site uses plain permalinks, it's https://www.example.org/?rest_route=/agoo/v1/webhooks instead.
Create the webhook endpoint
Choose one:
- Let the plugin do it. Paste a secret key (
agoo_sk_…) with thewebhooks:managescope into Secret key, choose the events you want, and select Create webhook endpoint. The plugin creates the endpoint in Agoo and stores its signing secret for you. - Do it yourself. In Agoo, open Console → Developers → Webhooks, add an endpoint with the receiver URL and the events you want, then copy its signing secret (
whsec_…) into Webhook signing secret in WordPress.
Use a test key or the test-mode console to create a test endpoint first. Test and live endpoints have different secrets.
Send a test event
Select Send test event. The plugin asks Agoo to send one to your receiver, and Last event received updates with the event type and time. If it doesn't, see troubleshooting.
Then hook your own code into the events: see webhooks and hooks.
How keys are stored
| Setting | Stored | Sent to the browser |
|---|---|---|
| Publishable key | In the agoo_settings option, as is | Yes. It's printed in pages that show a widget, by design. |
| Secret key | Encrypted, in the agoo_settings option | Never |
| Webhook signing secret | Encrypted, in the agoo_settings option | Never |
- Encryption. The secret key and webhook secret are encrypted with libsodium (
sodium_crypto_secretbox), using a key derived from your site's WordPress salts inwp-config.php. A copy of your database alone doesn't reveal them. WordPress includes a sodium compatibility library, so no extra PHP extension is needed. - Never shown again. After saving, the settings screen shows only the last four characters. To change a secret, paste a new one.
- If your salts change, for example after a security clean-up, the plugin can no longer decrypt the secrets. It tells you on the settings screen; paste them again.
- Admins only. Only users with the
manage_optionscapability can see or change the settings.
Keep secrets in wp-config.php instead
If you manage configuration in code or through your host's environment, define constants in wp-config.php. They take priority over the settings screen, which then shows them as read-only:
define( 'AGOO_PUBLISHABLE_KEY', 'agoo_pk_live_…' );
define( 'AGOO_SECRET_KEY', getenv( 'AGOO_SECRET_KEY' ) );
define( 'AGOO_WEBHOOK_SECRET', getenv( 'AGOO_WEBHOOK_SECRET' ) );Constants are not encrypted by the plugin, so keep wp-config.php out of version control and readable only by the web server.
Uninstalling
Deactivating the plugin removes the widgets from your pages (shortcodes are left as plain text) and stops the receiver. Deleting it also removes the agoo_settings option and the list of processed webhook IDs. It doesn't delete anything in Agoo: delete the webhook endpoint in Console → Developers → Webhooks and revoke any keys you no longer need.
Troubleshooting
Check that you pasted a publishable key (agoo_pk_…), not a secret key, and that it hasn't been revoked. Secret keys are refused in that field so
they can't end up in your pages.
Check that your site is reachable over HTTPS from the internet (not only on a staging network), that a security plugin or firewall isn't blocking
POST requests to /wp-json/, and that the endpoint in Agoo has your exact receiver URL. In Agoo, the endpoint's delivery log shows the response
your site gave.
The signing secret doesn't match the endpoint. Copy it again from Agoo, making sure test and live aren't mixed up. Also check that your server's clock is correct: events more than 5 minutes old are rejected.
Exclude https://js.agoo.ardent.africa/v1/embed.js from script combining, minification and delaying. The script must load as is.