Grant access duration
Control how long a visitor stays unlocked after passing an action-based access rule before they have to verify again.
Once a visitor passes an action-based rule — Passcode, Secret link, Subscribe to unlock, or Confirmation prompt — the app remembers that they're allowed in, so they aren't asked to verify on every page load. Grant access duration controls exactly how long that memory lasts before the visitor has to verify again.
Reach this setting
Open Locks and create a new lock, or open an existing one to edit it.
On the Unlock rules tab, add an access key with one of the action-based rules: Passcode, Secret link, Subscribe to unlock, or Confirmation prompt, in the main column.
Inside that rule's settings, in the same main column, find the Grant access (optional) field. This is a per-rule setting, not part of the Blocked visitor behavior sidebar panel.

Choose your duration (see below) and click Save.
Session-only vs. a fixed duration
Leave the field blank — the app remembers a verified visitor only for their current browser session. As soon as they close their browser, that memory is gone and they'll need to verify again the next time they visit.
Enter a number and pick a unit — minutes, hours, or days — for a fixed duration. The countdown starts the moment access is granted, not from when the browser is closed, so the visitor stays unlocked for exactly that long even across multiple visits, until the duration runs out.
It's a per-browser cookie, not an account setting
Grant access duration is stored as a cookie in the visitor's browser, not as a setting on their Shopify customer account. That means:
A visitor who verifies on their phone won't be automatically remembered when they switch to their laptop, or to a different browser on the same device.
Clearing cookies, using a private/incognito window, or switching browsers resets the memory, even within the duration you set.
Exception — Confirmation prompt's "remember for signed-in customers" toggle. If that toggle is turned on for a Confirmation prompt rule, a signed-in customer's confirmation is remembered differently: it's stored in the browser's local storage tied to that customer, and it has no expiry at all — it doesn't follow the duration set here, and it doesn't reset when the browser session ends. See Confirmation prompt for details on that toggle.
Related docs
Last updated
Was this helpful?