This recipe adds a Certificates section to a customer account area you built yourself, for example on WordPress, with Shopify handling customers and orders. The same steps work for any headless storefront.
How it fits together
- Your site already knows who the signed-in customer is (through Shopify customer login).
- Your server asks Authentica for that customer's certificates using your API key.
- Your page shows them in your design. Each card links to the certificate's verification page, which handles the PDF download and ownership transfer.
Set up
Create a key
In Authentica: Settings → Developer API → Create API key (Pro plan).Store it on the server
On WordPress, adddefine('AUTHENTICA_API_KEY', 'auth_live_...');towp-config.php. Never print it into a page.Add the code below
Put it in your theme or a small plugin, and call it from your account template.
WordPress example
function authentica_certificates_for(string $email): array {
$key = 'authentica_certs_' . md5(strtolower($email));
$cache = get_transient($key);
if ($cache !== false) return $cache;
$res = wp_remote_get(
'https://authentica.api.miko.co.nz/v1/certificates?status=all&email=' . rawurlencode($email),
['headers' => ['Authorization' => 'Bearer ' . AUTHENTICA_API_KEY], 'timeout' => 10]
);
if (is_wp_error($res) || wp_remote_retrieve_response_code($res) !== 200) return [];
$certs = json_decode(wp_remote_retrieve_body($res), true)['certificates'] ?? [];
set_transient($key, $certs, 5 * MINUTE_IN_SECONDS);
return $certs;
}
// In your "Certificates" template, for the signed-in customer:
foreach (authentica_certificates_for($customer_email) as $c) {
printf(
'<div class="cert-card"><h3>%s</h3><p>%s</p><p>Edition %s · %s</p><a href="%s">View certificate</a></div>',
esc_html($c['product']['title']),
esc_html($c['product']['variant'] ?? ''),
esc_html($c['edition']['formatted'] ?? '-'),
esc_html($c['status']),
esc_url($c['verifyUrl'])
);
}
Keeping it current
| Approach | Best for |
|---|---|
| Ask when the page opens (the example above, cached 5 minutes) | Most stores. Always correct, nothing to keep in sync. |
Keep your own copy: load everything once, then webhooks plus an hourly updated_since check | Large catalogues, search across certificates, or showing certificates in other parts of your site. |
Checklist before launch
- The API key is only on your server and not in any page source.
- The email you send is the signed-in customer's, never one typed into a form.
- Revoked certificates are shown as revoked, or hidden, rather than as valid.
- "View certificate" opens
verifyUrl, so buyers get the PDF and ownership transfer.
Related articles