Cart API
Customer-facing REST API for shopping cart state, line items, coupons, and guest session hydration.
Overview
The WooNooW Cart API provides customer-facing endpoints for managing the shopping cart. It operates directly against WooCommerce's session and cart engine, enabling seamless synchronization between Single Page Applications (SPAs) and server-side WooCommerce plugins.
- Controller:
WooNooW\Frontend\CartController - Namespace:
woonoow/v1 - Base URL:
https://your-store.com/wp-json/woonoow/v1
Session Architecture & Cookies
1. Guest Authentication Bypass
The WordPress REST API enforces nonce verification for cookie-authenticated sessions by default. To allow guest visitors to manage a cart without receiving rest_cookie_invalid_nonce errors, WooNooW registers a filter on rest_authentication_errors:
2. Authoritative Cart Hydration
In standard WordPress REST API requests, WC()->cart is not automatically initialized. Every Cart API endpoint calls CartController::ensure_cart_initialized():
- Checks if
WC()->sessionexists; if not, callsWC()->initialize_session(). - Checks if
WC()->cartexists; if not, initializesWC()->cartand loads contents viaWC()->cart->get_cart_from_session(). - If the cart is empty but a session key exists in the database, re-hydrates items from the session.
- If no session cookie exists yet, calls
WC()->session->set_customer_session_cookie(true).
3. Multi-Currency Context
When the multi-currency module is active, the cart response automatically contextualizes monetary formatting based on CurrencyContext::get_context(), including active currency code, symbol, formatting decimal places, and exchange rate ID.
Response Envelope & Error Format
Unlike internal order submission endpoints, the Cart API adheres to standard WordPress REST API conventions:
- Read Operations (
GET /cart): Return HTTP200 OKwith the authoritative Cart Object directly at the root. - Mutation Operations (
POST /cart/*): Return HTTP200 OKwith JSON payloads containing a descriptivemessagestring and the updatedcartobject (as well ascart_item_keyfor/cart/add). - Failure Responses: Return
WP_Errorobjects mapped to standard HTTP4xxand5xxstatus codes:
Authoritative Cart Object Schema
All cart endpoints return the authoritative cart structure:
Endpoints
1. Get Cart
Retrieves current cart contents, calculates totals, and returns the authoritative cart state.
Permission
- Public (Anonymous or Authenticated)
Response (HTTP 200)
Returns the Authoritative Cart Object directly.
2. Add to Cart
Adds a simple product or variation to the cart.
Parameters
Example Request
Response (HTTP 200)
Errors
404 invalid_product: The specifiedproduct_iddoes not exist.404 invalid_variation: The specifiedvariation_iddoes not exist.400 invalid_variation: Variation does not belong to the specified parent product.400 variation_not_available: The requested variation is out of stock.400 add_to_cart_failed: WooCommerce validation rejected addition (includes flattened error notices, e.g. stock limits).
3. Update Cart Item
Modifies the quantity of an existing line item in the cart.
Parameters
Example Request
Response (HTTP 200)
Errors
400 update_failed: Failed to update quantity (e.g. invalid key or stock limit exceeded).
4. Remove Item from Cart
Removes a single line item from the active cart.
Parameters
Example Request
Response (HTTP 200)
Errors
404 item_not_found: The specified cart item key does not exist in the active cart.400 remove_failed: WooCommerce failed to remove the line item.
5. Clear Cart
Removes all items, packages, and applied coupons from the cart.
Response (HTTP 200)
6. Apply Coupon
Applies a discount code to the cart session.
Parameters
Example Request
Response (HTTP 200)
Errors
400 coupon_code_required: An empty or whitespace coupon code was submitted.400 coupons_disabled: Store has disabled coupon usage.500 cart_error: Cart session could not be initialized.400 empty_cart: Cart contains no products to discount.400 coupon_currency_mismatch: Coupon is restricted to a currency different from the active currency context.400 coupon_failed: WooCommerce coupon validation failed (e.g. usage limit reached, minimum spend unmet, or expired).
7. Remove Coupon
Removes an applied discount code from the cart.
Parameters
Example Request
Response (HTTP 200)
Errors
400 coupon_code_required: The coupon code parameter was missing or empty.500 cart_error: Cart session could not be initialized.400 coupon_not_applied: The specified coupon code is not currently applied to the cart.400 remove_coupon_failed: Failed to remove coupon from the session.
Related Documentation
- Checkout REST API Reference — Submitting orders, quote calculation, and payment processing.
- Checkout Feature Guide — End-to-end purchasing lifecycle and auto-registration.
- Security Settings Configuration — Checkout rate limiting and bot protection.
Last updated Sep 11, 2026