System and security
Storefront IP blocking
Restrict access to one store's public frontend for explicitly selected IP addresses.
Purpose
Block the public storefront for selected individual IPv4 or IPv6 addresses without blocking admin access or payment webhooks.
How it works
- The module is disabled by default and accepts only individual IP addresses.
- It covers public storefront pages but excludes admin access, static assets and payment webhooks.
- The encrypted list is stored only in the database of that store.
- Disabling the module stops enforcement without deleting the saved list.
Step-by-step configuration
- Open Add-ons and select Storefront IP blocking.
- Add a valid IPv4 or IPv6 address and enable the module.
- Test both the storefront and admin access from a controlled address.
- Grant view and management permissions only to trusted team members.
Required permissions
Important information
Access depends on enabled store features, the user role and permissions assigned in Team.