Access control
Last updated:
For store owners.
Previous: Customers and orders · Next: AI overview
The owner manages the domains allowed to run the Widget and the IP addresses allowed to call the API under Settings → Domains & Access.
Only the owner can open and change this page.
Domains allowed to run the Widget
The Allowed storefront domains list controls which websites can use the store's Widget.
When adding a domain:
- Enter only the domain you want to use.
- Check both the version with
wwwand withoutwwwif the website uses both. - Add a separate test domain if you need to test on a staging environment.
- Remove domains that are no longer in use.
If the current domain is not in the list, the Widget may report Widget origin is not allowed for this shop.
IP addresses allowed to call the API
The list Allowed API IPs limits the sources that are allowed to call the store's API. Only add IPs or IP ranges confirmed by the technical person in charge.
An ISP or hosting provider may change its IP addresses. If a valid connection is suddenly rejected, check the current IP before changing the rule.
Save and test
- Review each domain and IP address.
- Select Save rules.
- Open the website on the domain you added and test the Widget.
- Retry the API connection from an authorized source if you have an IP configured.
If the Widget is still not displayed, check Show Widget, Preview IPs and the connection status of the module before changing the rule further.
Safety note
- Do not add domains or IP addresses from unknown sources.
- Don't delete all rules on your live store if you don't have a test plan in place.
- Keep a record of changes so your technical team can refer to it when troubleshooting.