Agent Stamp

A run of strange orders overnight ·

Bot order or AI agent order: how do I tell in WooCommerce?

Look at the Buyer stamp. A published agent, such as ChatGPT or Claude, is named. A browser where no person used the place-order control is Unattended. An order posted straight to the API is API, with the client named. A real click stays Human.

Why the difference matters

A card test, a scraper, and an assistant buying a gift for someone are three different visitors. Blocking all automation blocks the third one, and that one pays. Should I block AI agents?

What each stamp tells you

  • Claude (signed): the key checked out. That operator sent the request.
  • ChatGPT (declared): the user-agent named a published agent. It was not signed, so it is a claim.
  • Likely agent: a trusted click, but at least two signs that a program drove the browser, such as a click on the exact center of the button with almost no mouse movement. Not proof.
  • Unattended: a browser placed the order and no person used the checkout.
  • API (python-requests): a script created the order through the REST API instead of the checkout page.
  • Unknown: not an ordinary browser, and not an agent that proved itself. A forged agent name with a failed signature lands here.

A forged name

Anyone can send ChatGPT-User. That is why a name alone is marked declared, and a signature that fails is never given a name. A user-agent is a claim.

What the stamp is not

Unknown is not a fraud verdict, and no stamp cancels or holds an order. Your payment gateway still decides on payment risk. The Buyer filter puts a run of Unknown or API orders on one screen. If one is disputed, the order has a Download evidence link with the stamp, the user-agent, and a fingerprint of that record. What Unknown means.

Request a demo