Reference
wp-config constants
Every wp-config.php constant the Companion plugin reads — which are required, what each does, and a copy-paste block to start from.
The Companion plugin reads a small set of constants from WordPress’s wp-config.php. Two hold secrets that must never be stored in
the database. The rest let you pin a setting so it can’t be changed in wp-admin: when an RSC_* override constant is set and not
empty, it wins over the stored option, and the matching admin field is shown read-only.
All constants
Section titled “All constants”| Constant | Required? | Purpose | Notes |
|---|---|---|---|
RSC_JWT_SECRET |
Yes | HS256 signing secret for the storefront’s access tokens | Never stored in an option; the admin shows only “configured” or “missing”. Without it, sign-in, registration and token routes answer 500 jwt_secret_missing, and the Social Login tab shows a warning with a ready-to-paste define() line carrying a freshly generated secret. Changing it invalidates every access token already issued. |
RSC_STOREFRONT_SHARED_SECRET |
Strongly recommended in production when taking payments | Verifies the HMAC-signed X-RS-Shopper-Address header, so payment and checkout rate limits count each Shopper, not the storefront server |
Must equal the storefront’s STOREFRONT_SHARED_SECRET. Signatures are accepted within ±300 seconds. While it is missing, an admin notice warns, the per-Shopper Store API checkout limit stays off, and payment limits see the storefront as one client. Nothing is disabled. Can also be supplied through the rsc_storefront_shared_secret filter. |
RSC_FRONTEND_URL |
Recommended (or set Storefront URL in the admin) | The storefront’s public origin, such as https://shop.example.com, with no trailing slash |
Drives email links (verify, reset, back in stock), the header live preview, Product Preview links, product 301 redirects, policy page links and the Stripe payment-domain registration. |
RSC_GOOGLE_CLIENT_ID |
For Google sign-in | Google OAuth client id | Google needs only the client id; there is no Google secret. ID tokens are checked against it exactly. |
RSC_FACEBOOK_APP_ID |
For Facebook sign-in | Facebook app id | Facebook counts as enabled only when the app secret is also set. |
RSC_FACEBOOK_APP_SECRET |
For Facebook sign-in | Facebook app secret | Used for debug_token and appsecret_proof. Masked in the admin. |
RSC_TURNSTILE_ENABLED |
For Turnstile | Global Turnstile switch | Turnstile is enforced only when this switch and both keys are set (and the form’s own switch is on). Otherwise it fails open. |
RSC_TURNSTILE_SITE_KEY |
For Turnstile | Cloudflare Turnstile site key | Public; sent to the storefront. |
RSC_TURNSTILE_SECRET_KEY |
For Turnstile | Cloudflare Turnstile secret key | Never sent to the storefront. A save is refused if it equals the site key. |
RSC_DISABLE_EMAIL_VERIFICATION |
No. Development only. | true lets unverified accounts sign in and marks new registrations verified, with no email |
Meant for local and development sites without mail. Never set it in production. The rsc_require_email_verification filter does the same per site. |
RETAIL_STORE_COMPAION_LOAD_STYLE |
No | Boilerplate switch for the plugin’s front-end CSS | Defaults to true. |
RETAIL_STORE_COMPAION_LOAD_SCRIPTS |
No | Boilerplate switch for the plugin’s front-end JavaScript | Defaults to true. |
The plugin also defines its own path constants (RETAIL_STORE_COMPAION_FILE, RETAIL_STORE_COMPAION_BASENAME and similar). Those
are internal; don’t define them yourself.
A constant to leave undefined
Section titled “A constant to leave undefined”Don’t define WOOCOMMERCE_BIS_ALPHA_ENABLED. It switches on WooCommerce’s alpha back-in-stock feature, and the Companion ships its
own, and the two are not meant to run side by side.
Copy-paste block
Section titled “Copy-paste block”Add this above the /* That's all, stop editing! */ line in wp-config.php, then fill in the values. Generate fresh secrets for
every site; never reuse one between staging and production.
// --- Retail Store Companion -------------------------------------------------
// Required: signs the storefront's access tokens (HS256). A long random string.// The Social Login tab shows a ready-to-paste line with a freshly generated secret.define( 'RSC_JWT_SECRET', 'replace-with-a-long-random-secret' );
// Strongly recommended in production: the same value as the storefront's// STOREFRONT_SHARED_SECRET. Generate with: openssl rand -hex 32define( 'RSC_STOREFRONT_SHARED_SECRET', 'replace-with-the-shared-secret' );
// Optional: pin the storefront address (the admin field becomes read-only).define( 'RSC_FRONTEND_URL', 'https://shop.example.com' );
// Optional: pin social sign-in credentials.define( 'RSC_GOOGLE_CLIENT_ID', 'your-client-id.apps.googleusercontent.com' );define( 'RSC_FACEBOOK_APP_ID', 'your-facebook-app-id' );define( 'RSC_FACEBOOK_APP_SECRET', 'your-facebook-app-secret' );
// Optional: pin Cloudflare Turnstile.define( 'RSC_TURNSTILE_ENABLED', true );define( 'RSC_TURNSTILE_SITE_KEY', 'your-turnstile-site-key' );define( 'RSC_TURNSTILE_SECRET_KEY', 'your-turnstile-secret-key' );
// Development only: skip email verification. Never in production.// define( 'RSC_DISABLE_EMAIL_VERIFICATION', true );The storefront side
Section titled “The storefront side”Only one value is shared between the two deployments:
WordPress (wp-config.php) |
Storefront environment |
|---|---|
RSC_STOREFRONT_SHARED_SECRET |
STOREFRONT_SHARED_SECRET (same value) |
The storefront also needs its own AUTH_SECRET (for its session cookie), which is unrelated to RSC_JWT_SECRET; don’t reuse one
for the other. See environment variables.