=== NovaCraft API Builder ===

Contributors:      wpcrafthub
Tags:              woocommerce, rest-api, headless, jwt, api-keys
Requires at least: 6.4
Tested up to:      7.0
Requires PHP:      8.1
Stable tag:        1.0.0
License:           GPL-2.0-or-later
License URI:       https://www.gnu.org/licenses/gpl-2.0.html


The free, WordPress.org-compatible REST API foundation for headless WooCommerce stores — JWT authentication, API keys, caching, and a React admin UI.

== Description ==

NovaCraft API Builder for WordPress turns your WooCommerce store into a fully-featured headless commerce backend. It exposes a clean, versioned REST API under `/wp-json/novacraft/v1/` with:

* **JWT Authentication** — Issue access tokens (15 min TTL) and refresh tokens (30 days), with automatic rotation and revocation.
* **API Key Management** — Create `nc_live_*` and `nc_test_*` keys with granular permissions, IP allowlists, rate-limit overrides, and expiry dates.
* **Product Endpoints** — List, filter, sort, paginate, and retrieve products, variations, and reviews.
* **Category Endpoints** — Browse the WooCommerce category tree.
* **Order Endpoints** — Authenticated customers can view their order history and add order notes.
* **Customer Endpoints** — Manage profile, addresses, and order history.
* **Cart Endpoints** — Full headless cart: add/update/remove items, apply coupons, calculate shipping, and check out.
* **Caching** — Object-cache and transient fallback, ETag headers, tag-based invalidation.
* **Rate Limiting** — Sliding-window limiter with Redis or transient fallback. Account lockout after 5 failed logins.
* **React Admin UI** — Dashboard, API Key manager, API Explorer, request logs, and settings page.
* **Extensibility** — 6 filters and 6 actions so Pro / Enterprise add-ons can hook in without touching Core.

= Pro Features (Coming Soon) =

* RS256 keypair authentication
* Webhooks
* AI product recommendations
* Multi-currency support
* Subscription endpoints
* Cloud log aggregation

= Requirements =

* WordPress 6.4 or higher
* WooCommerce 8.0 or higher
* PHP 8.1 or higher

== Installation ==

1. Upload the `novacraft-api-builder` folder to `/wp-content/plugins/`.
2. Activate the plugin through the **Plugins** menu.
3. Navigate to **NovaCraft → Settings** to configure the API.
4. Create your first API key in **NovaCraft → API Keys**.

== Frequently Asked Questions ==

= Is this plugin free? =

Yes. NovaCraft API Builder for WordPress is free and open-source (GPL-2.0-or-later). Pro add-ons are available separately.

= Does this replace the built-in WooCommerce REST API? =

No. NovaCraft API Builder for WordPress runs alongside the WooCommerce REST API. It provides a separate, opinionated endpoint set optimised for headless storefronts.

= Which JavaScript frameworks does the API support? =

Any framework that can make HTTP requests: Next.js, Nuxt, SvelteKit, Astro, React Native, Vue, or plain `fetch()`.

= Where is the documentation? =

Full API documentation including an interactive OpenAPI explorer is available at [docs.wpcrafthub.com](https://docs.wpcrafthub.com).

= Is HPOS (High-Performance Order Storage) supported? =

Yes. All order queries use the WooCommerce `wc_get_orders()` function, which is HPOS-compatible.

== Screenshots ==

1. Dashboard — health widgets and recent API request log.
2. API Keys — create, copy, and revoke keys with per-key permissions.
3. API Explorer — browse all endpoints with live test functionality.
4. Logs — filterable request log with CSV export.
5. Settings — configure CORS, token TTL, rate limits, and caching.

== Source Code ==

This plugin is fully open source. The human-readable source files for all compiled JavaScript/CSS assets are publicly available on GitHub:

https://github.com/wpcrafthub/novacraft-api-builder

The admin dashboard is built with React (TypeScript) using Vite as the build tool. Source files are located in `admin/src/`. To regenerate the compiled assets in `admin/dist/`, run:

1. `npm install`
2. `npm run build`

== Screenshots ==

1. Dashboard overview with API health stats
2. API Explorer — browse and test all endpoints
3. API Key management screen
4. Request logs and monitoring
5. Settings page

== Changelog ==

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.0.0 =
Initial release — no upgrade steps required.
