Fastly Bot Detection and Blocking, With No Code Changes
WebDecoy now reads your Fastly logs to find crawlers that never run JavaScript, and blocks addresses in a Fastly ACL. No application code.
integrationWebDecoy is live on Shopify. Detect bot traffic, investigate risky orders, track AI crawlers and referrals, and choose your response with Shopify Flow.
WebDecoy is officially approved and publicly listed on the Shopify App Store. Starting today, October 2, 2026, merchants can install WebDecoy directly from Shopify and bring bot detection, order-risk evidence, actor investigation, and AI traffic reports into their Shopify admin.
This is a big launch for us. WebDecoy has always been about making automated traffic understandable: what touched your site, which signals made it suspicious, and what you can do with that evidence. Now that investigation fits the way a Shopify merchant actually works, from a storefront visit to an order waiting for review.
You should not have to become a security engineer to answer a practical question: is this activity worth investigating before my team fulfills the order? You should be able to open the app, inspect the evidence, and make a decision in the tools you already use.
For an online store, unwanted automation is more than an inflated traffic chart. Scrapers can retrieve catalog content. Automated sessions can interact with forms and carts. Suspicious orders create work for the people deciding what to fulfill, what to investigate, and what to escalate.
The difficult part is telling those activities apart. A proxy is context, not proof of fraud. A quiet visitor is not necessarily a bot. A crawler using an AI company’s name is making a claim, not demonstrating that the traffic is welcome. One isolated signal rarely tells the whole story.
WebDecoy combines observations into a reviewable picture. Storefront browser signals, request context, IP enrichment and decoy interactions contribute evidence. Sessions help connect that evidence to orders. Actor profiles help investigate related activity across visits and IPs when the available signals support correlation.
The Shopify app puts that picture where it is useful: in the detection details, the actor view, the Flagged Orders queue, and Shopify’s own order-risk tools.
A direct installation path. You can find WebDecoy in the Shopify App Store, approve the installation, and open it from Shopify admin. There is no separate WebDecoy login to create for the embedded app.
Storefront setup through an app embed. The Theme App Extension supplies the storefront integration. Enable WebDecoy Bot Detection in your theme editor’s App embeds panel and save. You do not need to paste a script into your theme files.
Checkout monitoring through Shopify’s pixel system. A separate Web Pixel reports supported checkout-funnel events, including checkout started, payment information submitted, and checkout completed. This is distinct from the storefront script; the theme embed does not run inside Shopify-hosted checkout.
Plans and billing through Shopify. Start with the Free plan or select a paid plan using Shopify’s pricing flow. Shopify displays the current price and applicable trial before approval, and handles billing.
An installation check with evidence. Setup & health shows the state of the storefront embed and checkout pixel. A labeled test lets you verify collection instead of assuming that a successful install means events are arriving.
The storefront integration collects browser fingerprints and behavioral signals, including indicators of automation. Server-derived request signals and IP enrichment add context about the request and its network origin, including proxies, VPNs and data centers.
Open a detection to inspect its score and supporting signals. The goal is to help you understand why an event deserves attention, rather than present a number without explanation.
Collection is not the same as comprehensive visibility. A scraper that does not run JavaScript and never touches a decoy may retrieve public pages without appearing in the app’s storefront reports. The integration reports what its collection surfaces observe.
WebDecoy adds hidden honeypot links and form fields to the storefront integration. These provide a different kind of evidence from a browser score: a client interacted with something that was placed as a trap.
Decoy paths are generated per store and served through Shopify’s signed App Proxy. You can add up to 20 custom path segments and control honeypot links and fields independently in Settings.
There is also an optional poison-response mode. A client that follows a trap can receive a decoy catalog with further decoy links. This is a configurable response at the decoy endpoint; it does not replace your actual product catalog.
An IP address is often an incomplete way to organize an investigation. Related activity can span several addresses, sessions and visits. WebDecoy’s actor views group detections using available fingerprint and session evidence.
In the embedded app, you can sort actors by threat, number of IPs or last seen, then open a profile to inspect its history. When correlation is available, orders can link back to the session and actor behind the observed activity.
An actor profile is an investigative grouping, not a guarantee that every matching request belongs to one unique person. Some identities are coarse or shared. The order-risk calculation treats coarse shared identities separately so another visitor’s aggregate threat is not borrowed into that order’s assessment.
The storefront integration writes a session reference into the cart. When an order is created, WebDecoy looks for matching detections and available actor context. Correlated suspicious orders can be tagged for review when tagging is enabled.
The app also supports native Shopify order risk assessments with supporting facts, plus order metafields for bot score and risk level. The order-details risk extension and Flagged Orders page give your team another way to inspect that evidence without rebuilding its fulfillment process.
In Flagged Orders, staff can record a review status and notes, including whether an order is legitimate or confirmed suspicious. Those decisions matter: a risk score should prompt investigation, and your team’s assessment should remain visible.
Correlation requires the relevant session and detection data. An order without that evidence cannot acquire a reliable history simply because the app is installed.
A finding becomes more useful when it fits an existing workflow. Pro and Agency include Shopify Flow triggers, and WebDecoy supplies a high-risk-order trigger with score, risk and actor context.
The app’s Automations page includes downloadable workflows to tag high-risk orders for review or add a review tag and notify staff. Import a template into Shopify Flow, review its settings, set the notification recipient where needed, and enable it when you are ready. Imported workflows start inactive and apply to new events after activation.
You can also build your own workflows using the order-tagging action. A separate cancellation action is available if you deliberately configure and enable a workflow that uses it.
The order-created handler does not independently cancel orders or block checkout. WebDecoy surfaces the evidence; cancellation automation is a merchant-controlled workflow. The supplied review and notification templates leave fulfillment decisions with your staff.
AI traffic has two different meanings for a merchant. A crawler may retrieve catalog content. A shopper may arrive after an AI assistant recommends a product. Those are different events and deserve different reports.
The AI Crawlers page groups observed activity into categories such as training, search and other crawlers. It also provides robots.txt guidance for expressing a policy toward training crawlers separately from AI search agents.
The AI Referrals page reports identifiable visits from assistants and AI search platforms, with platform breakdowns and referral records. It helps you investigate which services are sending visitors back to your store.
Referral counts are a floor. When a platform strips referral information, the app cannot reconstruct the missing source. Likewise, robots.txt is a request to cooperating crawlers, not a barrier that prevents a client from fetching public content.
A dashboard with no detections can mean several things. Your store may be quiet. A visitor’s browser may not deliver an event. The app embed may not be enabled on the published theme.
Setup & health makes those possibilities easier to investigate. It shows the storefront embed and checkout-pixel installation state, separate last-delivery times, and recorded delivery errors.
Create a test, open its storefront link, and return to confirm that the labeled detection arrived. This checks the installed script, Shopify proxy and detection-storage path. Test detections are excluded from traffic metrics, order review and enforcement, so setup verification does not become a fake threat in your reports.
Checkout-pixel delivery remains a separate check and can depend on customer consent and browser conditions. A successful storefront test does not establish that every checkout event will arrive.
That gives you a concrete starting point: a verified collection path and a place to investigate the activity your store produces.
| Plan | Monthly price, USD | Monthly detection allowance | Included plan features |
|---|---|---|---|
| Free | $0 | 500 | Honeypot links and form fields, dashboard analytics |
| Starter | $59 | 5,000 | Honeypots, order tagging, dashboard analytics |
| Pro | $149 | 100,000 | Order tagging, risk assessments, Shopify Flow triggers, priority support |
| Agency | $449 | 500,000 | Order tagging, risk assessments, Shopify Flow triggers, dedicated support |
Starter and Pro currently list 14-day free trials. Shopify’s plan-selection screen is the source for current prices, annual options, and trial availability before you approve a plan. The Free plan lets you begin without committing to a paid subscription.
The app uses Shopify-managed installation, a Theme App Extension, Web Pixels, authenticated App Proxy requests and verified webhook deliveries. Access tokens are encrypted at rest, and collection endpoints apply rate limits. Shopify customer-data request and redaction webhooks support the data-deletion lifecycle.
Uninstall deactivates collection. Redaction is a separate lifecycle operation; it should not be confused with simply uninstalling the app. Review our privacy policy and the App Store’s data-access disclosure before installing.
If your storefront runs on infrastructure outside Shopify, that deployment needs its own integration. Installing the Shopify app does not deploy a WAF or clearance validator in front of Shopify-hosted checkout. Our platform integrations explain the options for infrastructure you control.
Approval and publication mark the beginning of this launch. The next thing that matters is what merchants can see and do after installation: confirm collection, inspect the evidence, review orders, and choose a response that fits their store.
If you are dealing with suspicious traffic, unexplained automated activity, or orders that need closer inspection, WebDecoy is ready to evaluate inside Shopify.
For the complete capability list, setup steps, pricing and FAQs, visit WebDecoy for Shopify.
WebDecoy is publicly listed on the Shopify App Store at apps.shopify.com/webdecoy-bot-protection. Install the app, enable the WebDecoy Bot Detection app embed in your theme editor, and verify a labeled test in Setup & health.
The order-created handler flags correlated suspicious orders for review and does not independently cancel orders or stop checkout. Cancellation is available through a separate Shopify Flow action if you configure and enable your own workflow.
Yes. The Free plan includes 500 detections per month. Starter is $59 per month, Pro is $149 and Agency is $449, in USD. Starter and Pro list 14-day free trials. Shopify displays current pricing, annual options and trial availability before you approve a plan.
WebDecoy now reads your Fastly logs to find crawlers that never run JavaScript, and blocks addresses in a Fastly ACL. No application code.
integrationConnect Claude, ChatGPT or Codex to WebDecoy. Install bot detection in your app, prove it works, and ask what bots hit your site, from your assistant.
integrationWebDecoy's Netlify extension now protects selected paths. Install the sensor, enable clearance checks, verify the deployment, and roll out in Monitor mode.
integrationLike this post? Share it with your friends!
Get a personalized demo from our team.