BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
CoCart – Headless REST API for WooCommerce icon
Actively maintained Tested with WP 7.1 #17 in cart Freemium

CoCart – Headless REST API for WooCommerce

Ship your headless WooCommerce storefront faster. CoCart is the REST API built for Next.js, React, Vue, and any modern frontend — developer-first.

Active installs900+100+ tier
Downloads · 30d1.7K▲ +14.9% vs prev. 30d
Rating4.9/521 reviews
Health score87/100Excellent
All-time downloads101.2KSince Feb 2018
Support resolved—No recent threads
RequiresWP 6.7PHP 7.4+
Downloads · 7d489▲ +114.5% week over week
Our verdict

Safe pick

Yes — CoCart is a safe, well-maintained plugin to use in 2026. It runs on 900+ sites, is rated 4.9/5 and was last updated 2 days ago, and scores 87/100 on our health check.

  • Loved by users — 4.9/5 from 21 reviews
  • Actively developed — last update 2 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (900+ active installs)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

50100150Jul 4Aug 17Oct 1
Yesterday159
Daily average (1y)28
Peak day201Aug 24, 2026
Last 12 months10.1K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where CoCart stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
cart >100 6,726 Best cart plugins →
decoupled #3 134 Best decoupled plugins →
headless #1 471 Best headless plugins →
rest-api #9 7,484 Best rest-api plugins →
woocommerce >100 10,000 Best woocommerce plugins →

Version adoption

Share of active sites per release.

  • 4.946.0%
  • 4.823.0%
  • 3.910.8%
  • Other20.3%

Rating breakdown

★★★★★★★★★★ 4.9 from 21 reviews

  • 5★95.2%
  • 4★0.00%
  • 3★0.00%
  • 2★4.8%
  • 1★0.00%

About CoCart

From the official readme · v4.9.7

Description

You’ve chosen WooCommerce for your store. Now you want a modern frontend — React, Next.js, Astro, Vue — without being locked into WordPress themes. That’s exactly what CoCart is built for.

CoCart gives WooCommerce a proper frontend REST API: cookie-less session management built for stateless frontends, authentication that makes sense, and CORS support built-in. Cart sessions, authentication, and product data. Scale up when you’re ready.

In active development since 2018, with a ★4.9/5 rating from the developers who build headless stores with it every day.

🚀 Make your first API call in 2 minutes

Install CoCart and you’re immediately ready to call the API — no setup required:

curl -X POST https://your-store.com/wp-json/cocart/v2/cart/add-item \
  -H "Content-Type: application/json" \
  -d '{"id": "123", "quantity": 1}'

Want to explore before installing? Try a free sandbox →

See the full API reference →

💬 Loved by 1,000+ developers worldwide

Rated ★★★★★ 4.9/5 on WordPress.org.

★★★★★

“An excellent plugin, which makes building a headless WooCommerce experience a breeze. Easy to use, nearly zero setup time.” — Harald Schneider

★★★★★

“This plugin works great out of the box for adding products to the cart via API. The code is solid and functionality is as expected, thanks Sebastien!” — Scott Bolinger, Creator of Holler Box

★★★★★

“Thanks for doing such great work with this! Works exactly as expected and CoCart seems to have a nice community around it. The founder seems really devoted and that’s one of the key things for a plugin like this to live on and get the right updates in the future. We just got ourselves the lifetime subscription.” — Mighty Group Agency

See our full wall of love for more developer testimonials.

Why CoCart?

WooCommerce’s Store API can be used headless, but it was designed for the Gutenberg block editor ecosystem. Its session model relies on nonces passed via response headers — suited for anonymous single-session shoppers, but the nonce is tied to WordPress’s nonce lifecycle and less straightforward to persist across sessions or devices.

CoCart is purpose-built for headless from day one: cart sessions identified by a persistent key — no nonces, no cookies — a single unified endpoint set for both product and cart data, and authentication for customers that supports any shop requirement.

Features

🚀 Session management that works

  • 🔐 Cookie-less sessions — database-stored, built for concurrent requests and stateless frontends
  • 👤 Guest customer support — full cart session support for unauthenticated shoppers, no login required
  • 🔄 Load any session into checkout — hand off to WooCommerce’s native checkout with any payment gateway

🛒 Essential cart operations

  • ✅ Add, update, and remove items via simple POST/PUT/DELETE requests
  • 🔎 Product search — query by name, SKU, or ID, authenticated or not, with flexible filtering
  • 💸 Name Your Price support — donation-based and flexible pricing built in
  • 📦 Bulk cart requests — combine multiple operations into a single API call

💻 Developer experience, done right

  • 🔑 Flexible authentication — email, username, or phone login; no admin API keys to manage
  • 🌍 CORS support built in — first-party CORS handling; your frontend connects without configuration hell
  • 🧩 180+ filters — customize every response, add logic without writing new routes
  • 📊 Cart insights — monitor active, expiring, and expired sessions from the dashboard
  • 🛠 Works with your existing stack — built on WooCommerce Data Stores with familiar hooks for broad plugin compatibility

🎯 Battle-tested

  • Tested with every major WooCommerce release
  • Multisite compatible

Who builds with CoCart?

Frontend developers shipping storefronts in Next.js, React, Vue, Nuxt, Astro, Svelte, or Remix — keep WooCommerce as the commerce engine and own the entire frontend experience, from server components to fully static builds.

Mobile app developers building shopping apps in React Native, Flutter, Swift, or Kotlin — the same cart key works across devices, so a customer can start a cart on their phone and finish on the web.

Agencies delivering high-performance client storefronts — reuse one proven commerce backend across projects while every client gets a custom frontend, free of WordPress theme constraints.

Product teams going beyond the browser — progressive web apps with persistent carts, in-store kiosks, point-of-sale screens, even chat and voice commerce. Anywhere a customer can shop, CoCart can serve the cart.

Free vs. CoCart Plus

The free community version handles everything a headless cart needs: sessions, auth, CORS, cart operations, and product queries. It is actively maintained with security updates.

New features ship in CoCart Plus. When you’re ready to build a complete headless storefront — with coupons, shipping, fees, rate limiting, and checkout — Plus has you covered:

  • 🎫 Coupon Management — apply discounts and promo codes, boost conversions
  • 🚢 Shipping Calculations — real-time rates and method selection
  • 💰 Cart Fees — handling fees, rush charges, and custom pricing logic
  • 🥪 Advanced Batch API — multiple cart operations in a single request
  • 🕒 Rate Limiting — protect your API from abuse under load
  • 🧾 Checkout — complete orders with any WooCommerce-supported gateway (coming soon)
  • 💲 Subscription Support — new subscriptions and renewals (coming soon)

View CoCart Plus features and pricing →

👍 Add-ons

Free add-ons that extend the core:

SDKs & Tools

Official SDKs — authentication, session management, and cart operations out of the box:

  • cocart-js (TypeScript/JavaScript) — GitHub
  • cocart-php (PHP) — GitHub
  • cocart-python (Python) — GitHub
  • cocart-go (Go) — GitHub

More are also in development and look forward to your feedback.

Developer tools:

Need Support?

Free users: Post in the WordPress support forum or join the CoCart Discord community — a growing group of developers, agencies, and shop owners building headless stores together.

CoCart Plus customers receive priority support with faster response times.

Join the community on Discord →

More Information

💯 Credits

Developed and maintained by Sébastien Dumont
Founder of CoCart Headless, LLC.

Contributors & Developers

You can help translate “CoCart” into your language.

INTERESTED IN DEVELOPMENT?

Browse the code on GitHub, or follow the CoCart development blog for the latest development updates. You can also follow @cocartapi on Twitter to stay up to date about everything happening with CoCart.

Please share your experience

We’d love to hear what you have to say. Share your experience and help others discover CoCart. It helps to keep the plugin going strong, and is greatly appreciated.

Installation

Minimum Requirements

  • WordPress v6.7
  • WooCommerce v9.0
  • PHP v7.4

Recommended Requirements

  • WordPress v6.7 or higher.
  • WooCommerce v10.0 or higher.
  • PHP v8.2 or higher.

Automatic installation

Automatic installation is the easiest option as WordPress handles the file transfers itself and you don’t need to leave your web browser. To do an automatic install of CoCart, log in to your WordPress dashboard, navigate to the Plugins menu and click Add New.

In the search field type “CoCart” and click Search Plugins. Once you’ve found the plugin you can view details about it such as the point release, rating, and description. Most importantly of course, you can install it by simply clicking “Install Now”.

Manual installation

The manual installation method involves downloading the plugin and uploading it to your web server via your favorite FTP application. The WordPress codex contains instructions on how to do this here.

Upgrading

Review the changelog before upgrading. CoCart follows Semver — MAJOR versions may contain breaking API changes.

Frequently asked questions

Who is CoCart for?

Developers building headless or decoupled WooCommerce storefronts. If you can make HTTP requests and read JSON, you’re ready. No WordPress development experience required — CoCart abstracts the complexity and gives you clean, predictable API responses. Perfect for: Frontend developers building with React, Next.js, Astro, Vue, or any modern framework Agencies creating high-performance client storefronts Mobile app developers who need a reliable eCommerce API

How do I get started?

Install WooCommerce and configure your store, then install and activate CoCart. You’re immediately ready to call the API — no additional setup required. Check the installation section for requirements, then follow the API reference to start building.

What happens to the free community version if I don’t upgrade?

Nothing. The free community stays fully functional. It covers sessions, authentication, CORS, cart operations, and product queries — everything you need to build a working headless cart. CoCart Plus adds advanced features like coupons, shipping, fees, and rate limiting for when you need them.

Is my store or customer data sent to CoCart’s servers?

No. CoCart runs entirely on your WordPress server. No customer data, cart contents, or store information is ever sent to CoCart’s servers. The plugin collects no analytics without your consent. Full privacy policy →

Will my existing WooCommerce plugins still work?

Plugins that modify backend functionality — payment gateways, shipping, tax, inventory — continue to work. Plugins that only modify the PHP frontend (themes, shortcodes, widgets) won’t apply to the REST API layer, which is expected in a headless setup.

Why use CoCart instead of WooCommerce’s Store API?

WooCommerce’s Store API can be used headless, but it was designed for the Gutenberg block editor ecosystem. Its session model relies on nonces passed via response headers — suited for anonymous single-session shoppers, but tied to WordPress’s nonce lifecycle and less straightforward to persist across sessions or devices. CoCart is purpose-built for headless: cart sessions identified by a persistent key and authentication that supports any shop requirement.

Why does CoCart use a custom session handler?

Headless storefronts are stateless by nature — there’s no browser session to rely on, and concurrent requests are common. CoCart’s session handler is cookie-less, database-stored, and safe for concurrent requests, with full support for both guest and authenticated customers from day one.

Can I run WordPress on one domain and my storefront on another?

Yes — that’s the primary use case CoCart is built for. Enable CORS via the free CORS add-on or manually via the filter documented here.

Can I call other WordPress or WooCommerce APIs alongside CoCart?

Yes. CoCart doesn’t block or replace any other API. Once authenticated, your frontend can access CoCart endpoints, WooCommerce endpoints, and any custom endpoints you’ve built — all at the same time.

Can CoCart support SSO?

CoCart does not implement SSO itself — it authenticates customers against WordPress user accounts using Basic Auth or JWT (via add-on). It does not natively speak SAML, OAuth 2.0, or OIDC. That said, CoCart can work alongside SSO in a headless setup. The typical pattern is: Your identity provider (Google, Okta, Auth0, etc.) authenticates the user via your frontend. A WordPress SSO plugin (e.g. one handling OAuth 2.0 or SAML) creates or matches a WordPress user account for that identity. Your frontend then authenticates with CoCart using Basic Auth or JWT as that WordPress user. The SSO layer…

Does CoCart work on multisite?

Yes. Install and activate CoCart on each site where you want to use it.

Can I change the format of API responses?

Yes — there are 180+ filters available to customize responses, add fields, or remove data you don’t need.

Is “WooCommerce Shipping and Tax” plugin supported?

No — it restricts tax calculation to WooCommerce Blocks and Jetpack only. We don’t recommend it for headless setups. TaxJar for WooCommerce (v3.2.5+) is supported.

Does CoCart work with caching plugins like LiteSpeed or WP Rocket?

Yes. CoCart automatically excludes its API endpoints from page caching, so caching plugins won’t interfere with cart sessions or API responses. LiteSpeed Cache is explicitly supported out of the box. Though, some hosts may require manual configuration to exclude CoCart API endpoints.

How are cart sessions identified without cookies?

Each cart is assigned a unique cart key, which your frontend passes as a request header or query parameter on subsequent API calls. This makes sessions fully stateless and safe for concurrent requests — no cookies, no session conflicts. See the session documentation for implementation details.

Is there a hosted version, or does it run on my server?

CoCart runs entirely on your WordPress server — there’s no external service, no cloud dependency, and no data leaving your environment. You own your stack.

Where can I report bugs?

On the CoCart GitHub repository or in the #bug-report channel of the Discord community. Search first to avoid duplicates.

Where can I find more answers?

Check the full FAQ on cocartapi.com or browse the documentation.

Changelog

Security hardening for CoCart's REST authentication check. Update as soon as possible.

CoCart is open source and community-driven. Every release is tested, maintained, and published here on WordPress.org. Need more power? CoCart Plus unlocks advanced features and priority support.

v4.9.7 – 30th September, 2026

Security Patch

This release hardens how CoCart’s REST authentication check is scoped, ensuring WordPress’s own request verification is not bypassed on other REST endpoints. It is recommended that you update to this release as soon as possible.

  • REST API: Authentication error check now only applies to requests CoCart authenticated itself, so WordPress’s own nonce verification is no longer bypassed on other endpoints, including the batch endpoint. Reported by Naoki Kawahigashi.

v4.9.6 – 10th September, 2026

Improvement

Developer note: We don’t recommend using plain permalinks as it reduces the performance of lookup but we added support should it be the only option for you. e.g. ?rest_route=/cocart/v2/products

  • REST API: Recognize requests made via the ?rest_route= query parameter (plain permalinks).
  • WordPress Dashboard: Prevent enabling integrations without a loader module.

Compatibility

  • Tested with WooCommerce v11.1

v4.9.5 – 1st September, 2026

Security Patch

This release hardens how the cart session handler validates the cart key, however it is supplied — whether as a request parameter or via the header — ensuring a cart can only be loaded by the account it actually belongs to. It is recommended that you update to this release as soon as possible.

  • REST API: Session handler now verifies ownership of the requested cart key before loading cart data, regardless of whether it was supplied via parameter or header.

v4.9.4 – 24th August, 2026

[!IMPORTANT]
PHP 7.4 is once again the minimum requirement to install and use CoCart. While PHP 7.4, 8.0, and 8.1 are past end-of-life/security support, we recognize many hosts still run them, and we don’t want that to be a barrier to using CoCart. For the best performance and security, we still recommend running PHP 8.2 or later, but CoCart will continue to function correctly on 7.4+.

Change

  • Reverted PHP version to 7.4 as the minimum requirement to install and use CoCart.

v4.9.3 – 20th August, 2026

Change

  • REST API: Checks the product’s password directly rather than post_password_required() function.

Compatibility

  • Tested with WordPress 7.1

v4.9.2 – 12th August, 2026

Bug Fixes

  • REST API: Products that have password protection were still accessible. Now return as invalid ID when accessed directly and are excluded from results.

Compatibility

  • Tested with WooCommerce v11

Full changelog on WordPress.org →

Screenshots

The optional setup wizard gets your headless store configured in minutes.
The optional setup wizard gets your headless store configured in minutes.
Settings page — configure CORS, authentication, sessions, and features without touching code.
Settings page — configure CORS, authentication, sessions, and features without touching…
Integrations page — control which supported third-party plugins load during CoCart requests.
Integrations page — control which supported third-party plugins load during CoCart…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best CoCart alternatives

All cart plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Menu Cart for WooCommerce Menu Cart for WooCommerce Automatically displays a shopping cart in your menu bar. Works with WooCommerce and Easy… by WP Overnight 80K+ ★★★★★★★★★★ 4.6 (99) 4 days ago 87
2 Welcart e-Commerce Welcart e-Commerce Welcart is a free WordPress e-commerce plugin with the top market share in Japan. by info@welcart 10K+ ★★★★★★★★★★ 4.5 (6) 2 weeks ago 83
3 Simple Shopping Cart Simple Shopping Cart Lightweight, user-friendly plugin to sell products/services on WordPress. Easily add a… by mra13 / Team Tips and Tricks… 10K+ ★★★★★★★★★★ 4.6 (215) 2 months ago 81
4 Custom Add To Cart Button for WooCommerce Custom Add To Cart Button for WooCommerce Customize the Add to Cart buttons in WooCommerce by changing the text, adding a cart icon… by Kestrel 9K+ ★★★★★★★★★★ 3.9 (8) 2 years ago 40
5 Cart Popup for WooCommerce Cart Popup for WooCommerce Cart Popup for WooCommerce enables Ajax add-to-cart and displays an instant popup showing… by xootix 9K+ ★★★★★★★★★★ 4.4 (70) 4 months ago 71
6 FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler FluentCart A New Era of eCommerce Sell Subscriptions, Physical Products, Digital Downloads easier than ever. Built for… by WPManageNinja 9K+ ★★★★★★★★★★ 4.5 (41) 3 days ago 91
7 WP Menu Cart WP Menu Cart Automatically displays a shopping cart in your menu bar. Works with WooCommerce and Easy… by WP Overnight 8K+ ★★★★★★★★★★ 4.8 (23) 4 days ago 77
8 Ajax Cart AutoUpdate for WooCommerce Ajax Cart AutoUpdate for WooCommerce A light plugin that automatically updates cart page and mini-cart when product quantity is… by taisho 7K+ ★★★★★★★★★★ 5 (214) 6 years ago 46
9 Force Authentification Before Checkout for WooCommerce Force Authentification Before Checkout for WooCommerce Force customer to log in or register before checkout by linknacional 5K+ ★★★★★★★★★★ 5 (57) 7 days ago 89
10 Minimum Order Amount for WooCommerce Minimum Order Amount for WooCommerce Set a minimum order amount for WooCommerce, with a customizable notice shown in the cart… by dcurasi 2K+ ★★★★★★★★★★ 4.6 (14) 4 weeks ago 81

FAQ

CoCart: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 2, 2026

Is CoCart free?

Yes. CoCart is free to download and use from the official WordPress.org plugin directory. The developer also sells premium add-ons or a Pro version with extra features.

Is CoCart safe to use in 2026?

Yes — CoCart is a safe, well-maintained plugin to use in 2026. It runs on 900+ sites, is rated 4.9/5 and was last updated 2 days ago, and scores 87/100 on our health check.

How many websites use CoCart?

CoCart is active on 900+ WordPress websites and has been downloaded 101,232 times since it launched in February 2018. It was downloaded 1,748 times in the last 30 days.

Does CoCart work with WordPress 7.1?

Yes. The developer has tested CoCart up to WordPress 7.1.2, the latest release. It requires WordPress 6.7 or newer.

What PHP version does CoCart need?

CoCart requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was CoCart last updated?

The latest version, 4.9.7, was released on September 30, 2026 (2 days ago).

Who makes CoCart?

CoCart is developed and maintained by CoCart Headless.

What are the best alternatives to CoCart?

The most popular alternatives to CoCart are Menu Cart for WooCommerce (80K+ installs), Welcart e-Commerce (10K+ installs) and Simple Shopping Cart (10K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.