Whole website
Lock your entire storefront behind access rules, with an option to still allow the home page.
The Whole Website content type locks every page of your storefront behind the access rules you set, with one exception you control: whether the home page stays open. This is the right choice when you're building a store that should be invite-only, wholesale-only, or gated behind a single login screen across the board.
Create the lock
Open Locks in the app's navigation.
Click Create lock.
Give the lock a clear, descriptive name — you'll see this name in the Locks list, so make it something you'll recognize later (for example, "Whole store login required").
Choose Whole Website as the content to lock
On the Lock setup tab, in the content picker, select Whole Website.

Optionally tick Exclude url and list any paths that should stay public even though the rest of the site is locked — a contact page or a landing page you're running ads to, for example.
Whole Website locks may require a paid plan depending on your current plan.
Click the Unlock rules tab to continue.
Add an access rule
Add at least one rule that decides who gets through. For a whole-site lock, Logged-in customers or Passcode are common starting points — for example, requiring every visitor to sign in with a customer account before browsing anything.
Configure the rule's specific settings (see Access rules overview for the full catalogue of available rules).
If you need more than one condition to be true at once, add every required rule to the access key. All configured conditions must be satisfied. See Combining rules for details.
Choose a lock behavior
On the same Unlock rules tab, the right-hand sidebar has a Blocked visitor behavior panel. For a Whole Website lock, that panel has a single field:
Turn on Allow access to the home page if you want visitors to still be able to browse your storefront's home page without meeting any access rule — useful if you want the home page to work as a public landing page while everything else stays locked. Leave it off to lock the home page along with the rest of the site.

Decide what else blocked visitors see and what happens once they pass — for a whole-site lock this is usually a full lock screen rather than a hidden price or button. Review Lock behavior overview for the available options, such as redirecting visitors after they gain access or tagging their customer account once verified.
Save
Click Save. Once the app embed is enabled in your theme, the lock takes effect on your storefront immediately.
Your whole storefront is now protected by the rules you configured, with the home page handled according to the toggle you set.
Related docs
Last updated
Was this helpful?