Troubleshooting
The messages you are most likely to meet, what each one means, and what to do.
Updated September 25, 2026
Every message in the console tries to name its own fix. This page collects the ones that come up most, grouped by where you meet them.
Connecting a store
The store check reads your site the way your app will: without logging in. When it can’t, the message says what it saw, and each one has its fix below. If someone else looks after your site, press Copy steps for my developer under the message, where it’s shown. It copies the cause, the addresses and the fix as plain text, ready to send.
Three addresses on your site must answer the public (replace yourstore.com with your own address):
yourstore.com/wp-json/: WordPress’s REST API index. The store check reads it first.yourstore.com/wp-json/wc/store/: WooCommerce’s Store API. The app on your shoppers’ phones loads your products, categories and reviews from it.yourstore.com/wp-json/storetonative/: the StoreToNative plugin’s routes, used for pairing and shopper sign-in. They exist once the plugin is installed.
The StoreToNative plugin does not get around a block on these addresses. It needs them too.
This store is already connected to another StoreToNative account. One store powers one app. If both accounts are yours, contact support.
The approval page expired before you finished. WooCommerce’s approval link is short-lived. Reopen it from the wizard’s Access step.
Security plugin or firewall blocks the REST API
“We reached your site, but it wouldn’t let us read its public data at /wp-json.” Something refused our request for /wp-json, or served a page where WordPress’s data should be. The same rule often stops your shoppers’ phones too. Check the places that can block it:
- Security plugins, such as Wordfence, Solid Security or a “Disable REST API” plugin. Look for the setting that restricts the REST API to logged-in users. Allow public access, or add an exception for the three addresses above.
- Cloudflare. Bot Fight Mode and “I’m Under Attack” mode challenge requests that don’t come from a web browser, and the app is one of those. If either is on, turn it off and check again. If you added your own WAF rules or rate limits, add a rule that skips them for the three addresses above.
- Your host’s firewall, such as ModSecurity or Imunify360. Ask your host to allow public requests to the three addresses above.
Then press Check store again. If this isn’t the address your WordPress shop runs on, check that one instead.
REST API not found (Plain permalinks)
“We reached your site, but WordPress’s REST API isn’t at /wp-json.” WordPress only serves its REST API at /wp-json/ when permalinks are set to something other than Plain. In wp-admin, open Settings → Permalinks, choose Post name and press Save Changes. Then open yourstore.com/wp-json/ in a browser: you should see a page of JSON text, not a “page not found” or your home page.
If your permalinks are already set to something other than Plain, check that the address is the one your shop runs on.
The address answered, but not as WordPress
“That address answered /wp-json, but not with WordPress’s REST API data.” We can’t tell from our side which of several things happened, so open yourstore.com/wp-json/ in a private browser window and look:
- A verification or challenge page (“checking your browser”, a captcha): a security plugin, firewall or host rule is blocking it. See Security plugin or firewall blocks the REST API.
- Your site’s normal home page: permalinks are set to Plain. See REST API not found.
- Warnings or other text in front of the JSON: a plugin or theme is printing errors into it. Turn off on-screen errors (
WP_DEBUG_DISPLAY) and fix the warning it shows. - A site that isn’t WordPress: the address isn’t the WordPress site your shop runs on, for example when the shop lives on a subdomain such as
shop.yourbrand.com. Your WordPress address is under Settings → General → Site Address (URL).
WooCommerce or its APIs not listed
“We found WordPress, but its REST API doesn’t list WooCommerce”, or it lists only one of WooCommerce’s two APIs. Check that WooCommerce is installed and active. The app needs the public Store API (wc/store), and catalog sync needs the REST API (wc/v3). Both ship with WooCommerce, so if one is missing, a plugin, cache or firewall setting is hiding it from logged-out requests.
Secure connection (SSL certificate) failed
“We couldn’t open a secure (https) connection to that store.” Your site’s SSL certificate didn’t pass the check. It may have expired, be issued for a different address, be self-signed, or be missing an intermediate certificate. Some desktop browsers fetch a missing intermediate on their own, so the site can look fine to you while phones refuse it. Ask your host to install, renew or reinstall the certificate with its full chain. Free certificates such as Let’s Encrypt are standard, so a site with none can get one. A checker such as SSL Labs shows chain and expiry problems.
Address not found
“We couldn’t find that address.” The domain name doesn’t resolve. Check the spelling. If the domain is new or you just changed its DNS, wait a few hours and try again. Otherwise, check that the domain hasn’t expired.
Address redirects to another site
“That address redirects to a different site.” When we can read where it redirects, the wizard offers a button with that address. Use it, or type the address your shop ends up on. StoreToNative connects to your shop’s own address, not through a redirect.
Store unreachable
“We couldn’t reach that store, or it didn’t answer normally.” The site didn’t answer in time, refused the connection, or answered with a server error. Check the address, and that the site loads in a browser. If it does, your host may be refusing requests from servers. Ask them to allow the three addresses above.
The WordPress plugin
Pairing over http is refused. Your store must be served over https.
Site could not be verified. StoreToNative could not reach your site’s REST API during pairing. Common causes: a firewall blocking /wp-json/storetonative/, a host with a single PHP worker, a per-process object cache, or a site slower than ten seconds. Generate a new code after fixing it; the old one is spent.
Shopper accounts switch is inert. The plugin must be paired and new enough to report shopper sign-in. Update it and check the plugin card on the WooCommerce tab.
A shopper cannot sign in. Store staff accounts (administrators, shop managers, editors, authors) are blocked on purpose. Use a customer account.
Syncing
Your store address now redirects to a different domain. Press Change store on the WooCommerce tab and enter the new address.
Too many products. Contact us and we raise the allowance.
Webhooks: Pending. They register after the first sync completes with API keys in place. Run Sync now.
Builds
A build is already running for this app. One at a time. Wait for it to finish.
The build machine is busy right now or offline. Try again in a few minutes.
This workspace has hit its daily build limit. Wait until tomorrow, and remember most changes do not need a build.
Store builds are refused until the app id is set. Set it on the Builds page; it is locked after the first build.
Builds are paused. Either the trial has ended or a payment failed. See the Billing page.
Publishing
This build shipped the default icon or has your old app icon. The icon lives in the binary. Upload the icon in Design studio → Branding and make a new build.
Privacy policy URL missing. Neither store reviews an app without one. Add it under Design studio → Contact & legal.
Individual App Store Connect keys do not work. Create a Team key with the Admin role under Users and Access → Integrations.
Apple is waiting for an agreement to be accepted. Your key is fine; do not make a new one. The Account Holder accepts Apple’s updated agreement (sign in at developer.apple.com/account, and check App Store Connect → Business), then try again with the same key.
Saved as a draft on Play production. Open the release in Play Console and roll it out.
Apple rejected the app under guideline 4.3. Use the Rejection playbook on the Publish page. The usual fixes: your own name in the app name, your own icon and colours, policy pages on your own domain, and a description you wrote.
Push
Not enough notification opens yet. Best send time needs 50 opens in the last 90 days.
Send to 0 devices. Nobody in that audience has the app with notifications allowed. Check the Push add-on is on and try Everyone.
iPhones are not receiving pushes. Add the APNs push key under Publish → App Store → Apple keys.
Webhooks and API
Endpoint switched off after ten consecutive failures. Fix the endpoint, then switch it back on from its card.
Signature does not verify. Compute the HMAC over the raw request body, not a re-serialised copy, and check the clock: deliveries older than five minutes must be rejected, so a wrong clock on your server rejects everything.
Team and account
All seats are taken. Remove a member or upgrade.
This invitation was sent to a different email address. Sign in with the address the invitation was sent to, or ask for a new invitation.
Your coupon was refused. It has been used, has expired, is fully redeemed, or is not valid for this workspace.
Still stuck? Open a ticket from Support in the console, or contact us.