wc-payment-tokens

Installation
SKILL.md

WooCommerce payment tokens

Payment tokens are WooCommerce's saved-payment-method records. They connect a WooCommerce customer to a gateway-owned provider reference and type-specific safe display metadata. Card type, last4, and expiry exist only on card-token subclasses. They are not raw card storage. Never store PAN/card numbers, CVV, magnetic stripe data, or full bank credentials in WooCommerce token fields or meta.

Misconception this skill corrects

"I have a token ID from the browser, so I can charge it."

A token ID is user-controlled input. Load the token server-side and verify ownership, gateway ID, and token type before using it. WooCommerce's built-in My Account delete/default handlers check both nonce and ownership; custom endpoints must do the same.

When to use this skill

Trigger when ANY of the following is true:

Installs
1
GitHub Stars
22
First Seen
1 day ago
wc-payment-tokens — lonsdale201/wp-agent-skills