Order Invoicer

Cloudflare, WAF and firewalls: allowing Order Invoicer

How to allowlist Order Invoicer in Cloudflare, Sucuri, Wordfence or a WAF using its dedicated user-agent

Order Invoicer calls your store's API (Shopify, WooCommerce, Prestashop, Magento, Sylius, Odoo…) and your invoicing tool's API from our servers. If a protection service sits in front of your site — Cloudflare, Sucuri, Wordfence, your host's WAF — those calls can be mistaken for unwanted automated traffic and blocked.

The typical symptom: the sync stops, the connector is paused, and the logs show HTTP 403, a "Just a moment…" page, a JavaScript challenge or a captcha.

Our user-agent

Every outgoing request from Order Invoicer sends the same User-Agent header:

OrderInvoicer (+https://orderinvoicer.com)

That is the criterion to use to identify and allow us. It is the same for every connector and every integration, and does not change from one customer to another.

We have no fixed outbound IP address: our servers and those of our hosting providers can change IP without notice. Do not allowlist by IP address — use the user-agent, optionally combined with the API path.

Cloudflare

Create a WAF skip rule

  1. Open the Cloudflare dashboard and select your domain.

  2. Go to Security → WAF → Custom rules.

  3. Click Create rule and name it, for example, Allow Order Invoicer.

  4. Use the expression editor with:

    (http.user_agent contains "OrderInvoicer")

    To be stricter, add your store's API path — for WooCommerce, for example:

    (http.user_agent contains "OrderInvoicer" and starts_with(http.request.uri.path, "/wp-json/wc/"))
  5. Choose the Skip action, then tick at least All remaining custom rules, Managed rules, Rate limiting rules, Super Bot Fight Mode and Browser Integrity Check.

  6. Deploy the rule, then move it to the top of the custom rules list.

Bot Fight Mode

Bot Fight Mode and Super Bot Fight Mode (Security → Bots) challenge automated traffic, including legitimate traffic. If you use them:

  • create the Skip rule above, which takes precedence, or
  • set "definitely automated" to Allow for API paths,
  • turn Bot Fight Mode off (free plan) if you cannot create an exception: that version has no fine-grained exclusions.

Other Cloudflare settings to check

  • Under Attack Mode: it challenges every request, including ours. Turn it off or add the skip rule.
  • Rate limiting: our syncs burst requests during an initial import. Exclude our user-agent from rate limiting rules.
  • Page Rules / Configuration Rules setting "Security Level: High" on API paths.
  • Cloudflare Access (Zero Trust): if it protects your domain or back office, the API is unreachable without a token. Add a Bypass policy on the API path.

Sucuri

In the Sucuri firewall, open Firewall → Settings → Whitelist and add an exception for the API path. If your plan allows it, build the rule on the OrderInvoicer user-agent rather than on an IP.

WordPress security plugins

Wordfence, Solid Security (formerly iThemes), All-In-One WP Security, NinjaFirewall:

  • add an allowlist entry for the OrderInvoicer user-agent;
  • allow the /wp-json/wc/v3/ path (WooCommerce);
  • check that "fake bot" or non-browser traffic blocking does not catch us;
  • disable rate limiting rules for that user-agent.

ModSecurity and host WAFs

On an application WAF (ModSecurity, OVH, o2switch, Kinsta, WP Engine…), ask your host to add an exception for requests carrying the OrderInvoicer user-agent to your store's API path. Generic OWASP rules frequently block JSON POST requests to REST APIs.

Check that the block is gone

From any terminal, replay a request with our user-agent:

curl -I -A "OrderInvoicer (+https://orderinvoicer.com)" https://your-store.com/wp-json/wc/v3/

A 200 or 401 means you get through the firewall (401 only means API credentials are missing). A 403, a 503 or a challenge page means the block is still active.

Then, in Order Invoicer, open your connector and click Test connection & reactivate.

See also

Still blocked? Email us at contact@orderinvoicer.com with the date and time of a block: we will tell you the exact request to look for in your logs.

On this page