SHOPIFY · EARLY ACCESS

Bot and AI-agent security for Shopify.

Understand observable activity, review the reasons behind a decision, and see exactly which store actions your integration can cover.

Discuss a pilot

Help shape the first scoped monitoring evaluations.

We’re starting with three to five conversations about a specific store problem. Keep existing protections in place. Agree an evidence question and a review date before any monitor-only installation; live-store readiness still needs to be established.

Read the design-partner offer

For stores with an automation problem worth understanding.

Repeated cart activity, unwanted scraping or unusual account activity can deserve investigation. Start with the business problem and the evidence your store can provide. Neither an abandoned cart nor a fast shopper establishes abuse.

Coverage you can inspect.

Stable Shopify API 2026-07; platform review 2026-09-24. Initial observations were received on a Basic development store. Each merchant still needs a connection and coverage check; installed telemetry does not mean active protection.

Monitor only

Storefront pages

Consent-permitted theme observations and page/product pixel events.

Evidence
Untrusted browser evidence
Control
Monitor only
Required
Merchant activates theme embed; pixel requires granted scopes and activation

No edge firewall. Disabled scripts and non-executing clients are outside this observation path.

Development observation, 25 September 2026: consent-permitted page and product events received. Merchant-store setup remains to be verified.
Unavailable

Shopify forms and accounts

Only page events where the activated theme runs.

Evidence
No authenticated customer identity from browser data
Control
Unavailable
Required
A supported server intervention would need separate integration and testing

No native form, login or account blocking; new customer-account pages are not theme surfaces.

Live platform test: pending
Monitor only

Cart activity

Cart viewed, item added and item removed pixel events.

Evidence
Untrusted browser evidence
Control
Monitor only; static quantity validation remains unactivated
Required
Active pixel with read_customer_events and write_pixels

Browser events do not establish execution, cart ownership or protection of direct API requests.

Development observation, 25 September 2026: item-added events received. Cart views, removals and direct paths still need live checks.
Unactivated

Ordinary and accelerated checkout

Consent-permitted checkout progression pixel events; Function receives Shopify cart quantities.

Evidence
Pixels are untrusted; Function input is platform supplied
Control
Static maximum cart quantity Function source, disabled by default
Required
Approved public app on supported plans, or custom app on Plus; merchant activation and live proof

No active checkout protection in this build. Remote Blokk scoring requires Enterprise custom distribution and approved network access.

Development observation, 25 September 2026: ordinary checkout start received. Completed, accelerated and enforcement journeys still need live checks.
Unavailable

Payment attempts

No raw payment-attempt feed collected.

Evidence
Checkout completion is not a payment-abuse verdict
Control
Unavailable
Required
Separate platform capability and data approval required

No payment credentials, card-testing prevention guarantee, or inference of fraud from abandoned checkout.

Live platform test: pending
Unactivated

Post-order outcomes

Signed order lifecycle webhooks when approved scopes are granted.

Evidence
Platform-authenticated source; buyer intent remains unknown
Control
Observation after the event
Required
read_orders and applicable protected customer data approval

An order webhook does not prove a prevented action; browser checkout completion is not an authoritative order outcome.

Live platform test: pending
Unavailable

Headless and other platform paths

No automatic theme/pixel coverage assumed.

Evidence
Unknown outside an explicit integration
Control
Unavailable in this integration
Required
Surface-specific supported integration and live coverage test

Validation has documented exceptions including Create Order API, POS and recurring subscription orders.

Live platform test: pending

Guided installation, with visible checkpoints.

  1. Confirm eligibility. Agree a pilot scope and authorised install route. Public distribution and app review are still pending.
  2. Install and verify access. The supported embedded flow verifies the shop and granted scopes. Monitoring needs read_customer_events and write_pixels; order access is separate and requires approval where applicable.
  3. Activate the components. Enable the theme embed in the theme editor and configure the pixel. Privacy settings determine whether and when observations arrive. Installation alone does not complete setup.
  4. Confirm first evidence. Inspect a real session, its source and coverage status. Check ordinary navigation, keyboard use, consent denial and disabled scripts.
  5. Stay in monitor mode. Review outcomes and limits before separately activating any supported intervention. The checkout Function remains unactivated in this build.

A result with reasons, not a verdict on a person.

The inspector below uses labelled synthetic data from the generic core to explain the evidence model. It is not a Shopify session, customer record or live result.

01 / INSPECT THE EVIDENCEPRIVATE ALPHA
B.Action inspector
Shadow mode
Recent actions
ACTIONOBSERVATION
Decision detailsevt_example_01
Browser automation indicatorBrowser-asserted
webdrivertrue

The browser reported an automation flag. This is a client assertion and can be changed or hidden. Automation can be welcome: this action was later confirmed legitimate.

Integrity ValidEvidence Available
Shadow mode · action allowed Outcome: Legitimate
Illustrative data — not a live detection result

Progress safely from evidence to policy.

New installations start in monitor mode. A policy match says “would have matched,” not “blocked.” Supported controls need an explicit surface, clear rule logic, a preview and reversible activation. Unsupported actions remain unavailable.

For the current checkout slice, deterministic quantity validation source exists but has not intercepted a live Shopify checkout. It is not adaptive bot scoring or card-testing prevention. A normal public app cannot assume a real-time call to Blokk during checkout.

Protect the ordinary journey.

Missing telemetry, fast interaction, keyboard navigation, autofill and a shared network are not sufficient reasons to reject a shopper. Crawler claims remain unverified without an appropriate trusted observation point. An authorised agent may be welcome; automation alone does not establish malicious intent.

Overrides, outcomes and diagnostics

A merchant needs a server-authenticated way to stop supported enforcement, and an honest explanation of configuration propagation. Review requested actions separately from executed effects. Keep later legitimate, abusive, unresolved and corrected outcomes visible. Integration errors are not “bots blocked.”

Before your pilot

Which Shopify plans are supported?

The monitoring pilot still needs validation on your store. Shopify Functions in public apps are supported across plans; custom apps using Functions require Plus. Remote validation fetch has additional Enterprise custom-app and network-approval restrictions. None of that establishes activation or tested coverage for Blokk.

Does Blokk stop card testing?

No demonstrated card-testing prevention is claimed. We do not collect raw payment attempts or card credentials. Checkout progression is observational and a post-order event cannot establish that an attempt was prevented.

Can I install from the App Store today?

No approved public listing is available. Request access so we can review the permitted pilot route, required setup and remaining gaps.

What does the pilot cost?

One bounded pilot, followed by an optional recurring package when its protection workflow is demonstrated. Coverage, observation allowance, support, review date and any fees are agreed in writing before onboarding. No public paid plan is available; discussing a pilot creates no charge. Read pilot pricing status.

GUIDED PILOT

Discuss a pilot

Share your business email, store and main problem. Context is optional. We review fit before arranging any installation; this form creates no subscription. The first step is a conversation about your workflow and the evidence a scoped evaluation could deliver.

For project contact only. Please don’t include passwords, API keys, customer records or sensitive examples.

By submitting, you ask us to contact you about this pilot request. Read the draft privacy notice.

Go deeper: Shopify bot protection and coverage, checkout abuse evidence and AI shopping agents.