Skip to content
weLabsweLabsStorefront Playbook
Live demoQuickstart

Reference

wp-config constants

Every wp-config.php constant the Companion plugin reads — which are required, what each does, and a copy-paste block to start from.

The Companion plugin reads a small set of constants from WordPress’s wp-config.php. Two hold secrets that must never be stored in the database. The rest let you pin a setting so it can’t be changed in wp-admin: when an RSC_* override constant is set and not empty, it wins over the stored option, and the matching admin field is shown read-only.

Constant Required? Purpose Notes
RSC_JWT_SECRET Yes HS256 signing secret for the storefront’s access tokens Never stored in an option; the admin shows only “configured” or “missing”. Without it, sign-in, registration and token routes answer 500 jwt_secret_missing, and the Social Login tab shows a warning with a ready-to-paste define() line carrying a freshly generated secret. Changing it invalidates every access token already issued.
RSC_STOREFRONT_SHARED_SECRET Strongly recommended in production when taking payments Verifies the HMAC-signed X-RS-Shopper-Address header, so payment and checkout rate limits count each Shopper, not the storefront server Must equal the storefront’s STOREFRONT_SHARED_SECRET. Signatures are accepted within ±300 seconds. While it is missing, an admin notice warns, the per-Shopper Store API checkout limit stays off, and payment limits see the storefront as one client. Nothing is disabled. Can also be supplied through the rsc_storefront_shared_secret filter.
RSC_FRONTEND_URL Recommended (or set Storefront URL in the admin) The storefront’s public origin, such as https://shop.example.com, with no trailing slash Drives email links (verify, reset, back in stock), the header live preview, Product Preview links, product 301 redirects, policy page links and the Stripe payment-domain registration.
RSC_GOOGLE_CLIENT_ID For Google sign-in Google OAuth client id Google needs only the client id; there is no Google secret. ID tokens are checked against it exactly.
RSC_FACEBOOK_APP_ID For Facebook sign-in Facebook app id Facebook counts as enabled only when the app secret is also set.
RSC_FACEBOOK_APP_SECRET For Facebook sign-in Facebook app secret Used for debug_token and appsecret_proof. Masked in the admin.
RSC_TURNSTILE_ENABLED For Turnstile Global Turnstile switch Turnstile is enforced only when this switch and both keys are set (and the form’s own switch is on). Otherwise it fails open.
RSC_TURNSTILE_SITE_KEY For Turnstile Cloudflare Turnstile site key Public; sent to the storefront.
RSC_TURNSTILE_SECRET_KEY For Turnstile Cloudflare Turnstile secret key Never sent to the storefront. A save is refused if it equals the site key.
RSC_DISABLE_EMAIL_VERIFICATION No. Development only. true lets unverified accounts sign in and marks new registrations verified, with no email Meant for local and development sites without mail. Never set it in production. The rsc_require_email_verification filter does the same per site.
RETAIL_STORE_COMPAION_LOAD_STYLE No Boilerplate switch for the plugin’s front-end CSS Defaults to true.
RETAIL_STORE_COMPAION_LOAD_SCRIPTS No Boilerplate switch for the plugin’s front-end JavaScript Defaults to true.

The plugin also defines its own path constants (RETAIL_STORE_COMPAION_FILE, RETAIL_STORE_COMPAION_BASENAME and similar). Those are internal; don’t define them yourself.

Don’t define WOOCOMMERCE_BIS_ALPHA_ENABLED. It switches on WooCommerce’s alpha back-in-stock feature, and the Companion ships its own, and the two are not meant to run side by side.

Add this above the /* That's all, stop editing! */ line in wp-config.php, then fill in the values. Generate fresh secrets for every site; never reuse one between staging and production.

// --- Retail Store Companion -------------------------------------------------
// Required: signs the storefront's access tokens (HS256). A long random string.
// The Social Login tab shows a ready-to-paste line with a freshly generated secret.
define( 'RSC_JWT_SECRET', 'replace-with-a-long-random-secret' );
// Strongly recommended in production: the same value as the storefront's
// STOREFRONT_SHARED_SECRET. Generate with: openssl rand -hex 32
define( 'RSC_STOREFRONT_SHARED_SECRET', 'replace-with-the-shared-secret' );
// Optional: pin the storefront address (the admin field becomes read-only).
define( 'RSC_FRONTEND_URL', 'https://shop.example.com' );
// Optional: pin social sign-in credentials.
define( 'RSC_GOOGLE_CLIENT_ID', 'your-client-id.apps.googleusercontent.com' );
define( 'RSC_FACEBOOK_APP_ID', 'your-facebook-app-id' );
define( 'RSC_FACEBOOK_APP_SECRET', 'your-facebook-app-secret' );
// Optional: pin Cloudflare Turnstile.
define( 'RSC_TURNSTILE_ENABLED', true );
define( 'RSC_TURNSTILE_SITE_KEY', 'your-turnstile-site-key' );
define( 'RSC_TURNSTILE_SECRET_KEY', 'your-turnstile-secret-key' );
// Development only: skip email verification. Never in production.
// define( 'RSC_DISABLE_EMAIL_VERIFICATION', true );

Only one value is shared between the two deployments:

WordPress (wp-config.php) Storefront environment
RSC_STOREFRONT_SHARED_SECRET STOREFRONT_SHARED_SECRET (same value)

The storefront also needs its own AUTH_SECRET (for its session cookie), which is unrelated to RSC_JWT_SECRET; don’t reuse one for the other. See environment variables.

Storefront Playbook · Built by weLabsFeaturesFAQTalk to us