Bot order or AI agent order: how do I tell in WooCommerce?
Look at the Buyer stamp. A published agent, such as ChatGPT or Claude, is named. A browser where no person used the place-order control is Unattended. An order posted straight to the API is API, with the client named. A real click stays Human.
Why the difference matters
A card test, a scraper, and an assistant buying a gift for someone are three different visitors. Blocking all automation blocks the third one, and that one pays. Should I block AI agents?
What each stamp tells you
- Claude (signed): the key checked out. That operator sent the request.
- ChatGPT (declared): the user-agent named a published agent. It was not signed, so it is a claim.
- Likely agent: a trusted click, but at least two signs that a program drove the browser, such as a click on the exact center of the button with almost no mouse movement. Not proof.
- Unattended: a browser placed the order and no person used the checkout.
- API (python-requests): a script created the order through the REST API instead of the checkout page.
- Unknown: not an ordinary browser, and not an agent that proved itself. A forged agent name with a failed signature lands here.
A forged name
Anyone can send ChatGPT-User. That is why a name alone is marked declared, and a signature that fails is never given a name. A user-agent is a claim.
What the stamp is not
Unknown is not a fraud verdict, and no stamp cancels or holds an order. Your payment gateway still decides on payment risk. The Buyer filter puts a run of Unknown or API orders on one screen. If one is disputed, the order has a Download evidence link with the stamp, the user-agent, and a fingerprint of that record. What Unknown means.