For the complete documentation index, see llms.txt. This page is also available as Markdown.

Grant access duration

Control how long a visitor stays unlocked after passing an action-based access rule before they have to verify again.

Once a visitor passes an action-based rule — Passcode, Secret link, Subscribe to unlock, or Confirmation prompt — the app remembers that they're allowed in, so they aren't asked to verify on every page load. Grant access duration controls exactly how long that memory lasts before the visitor has to verify again.

Reach this setting

  1. Open Locks and create a new lock, or open an existing one to edit it.

  2. On the Unlock rules tab, add an access key with one of the action-based rules: Passcode, Secret link, Subscribe to unlock, or Confirmation prompt, in the main column.

  3. Inside that rule's settings, in the same main column, find the Grant access (optional) field. This is a per-rule setting, not part of the Blocked visitor behavior sidebar panel.

The Grant access duration field showing a number input connected to a day, hour, or minutes dropdown.
Enter a number and choose a unit to set how long a visitor stays unlocked after verifying.
  1. Choose your duration (see below) and click Save.

Session-only vs. a fixed duration

  • Leave the field blank — the app remembers a verified visitor only for their current browser session. As soon as they close their browser, that memory is gone and they'll need to verify again the next time they visit.

  • Enter a number and pick a unit — minutes, hours, or days — for a fixed duration. The countdown starts the moment access is granted, not from when the browser is closed, so the visitor stays unlocked for exactly that long even across multiple visits, until the duration runs out.

The duration starts counting as soon as access is granted. The page itself won't automatically refresh or re-lock itself the instant the timer expires — the app re-checks access the next time the visitor loads or navigates to a protected page.

Grant access duration is stored as a cookie in the visitor's browser, not as a setting on their Shopify customer account. That means:

  • A visitor who verifies on their phone won't be automatically remembered when they switch to their laptop, or to a different browser on the same device.

  • Clearing cookies, using a private/incognito window, or switching browsers resets the memory, even within the duration you set.

Last updated

Was this helpful?