Country Shield user guide.

Follow the complete setup sequence, understand each rule, test safely, and resolve the most common storefront and billing issues.

Before you start

You need a Shopify account that can install apps and customize the active theme. Keep your permanent myshopify.com domain available; a custom storefront domain is not used for installation.

Country Shield is safest to launch with a small denylist. Move to allowlist or strict mode only after the basic storefront check is working.

Install Country Shield

1

Start from Shopify

Use the Country Shield App Store listing or an approved Shopify admin install surface. Country Shield does not ask you to type your store domain to begin installation.

2

Review requested permissions

Shopify shows the app authorization screen before installation. Approve the install to open the embedded Country Shield admin.

3

Confirm the store shown in the header

The merchant app displays the permanent store domain and current plan. Stop and contact support if the domain is not the store you intended to configure.

Create your first protection rule

1

Open Protection rules

Choose Denylist to block only selected countries. Choose Allowlist to block every country except your selections.

2

Add countries

Free stores can add two countries. Pro and Premium remove the country limit. Paid plans can also add supported regions or states.

3

Choose an action and scope

Start with Block and Whole store. Redirect and challenge are paid actions. Checkout-only applies the rule only on checkout paths.

4

Save changes

The right-side preview summarizes the policy. Country Shield enforces plan limits on the server when you save.

Enable the theme app extension

Rules are not applied to storefront traffic until Shopify loads the Country Shield app embed.

1

Open the theme editor

In Shopify admin, go to Online Store → Themes, then choose Customize for the active theme.

2

Open App embeds

Choose the App embeds icon in the theme editor. Find Country Shield and switch it on.

3

Save the theme

Use Shopify's Save control. Return to Country Shield and confirm that you enabled the extension.

Changing or publishing a new theme can require you to check App embeds again. Verify Country Shield after any theme change.

Test without locking yourself out

  1. Open Protection rules and scroll to Test your rule.
  2. Select a country and use Preview decision. This evaluates the saved policy without creating a fake storefront request.
  3. Open the live storefront in a private browser window.
  4. Use a location you intentionally blocked and confirm the expected action.
  5. Return to Overview and confirm the setup checklist is complete.

When testing allowlist mode, include your own location before saving. When testing strict mode, confirm both an allowed and blocked location.

Understand actions and scope

Block

Matched visitors see the Country Shield interstitial. Paid plans may use a custom message.

Redirect

Matched visitors are sent to the HTTPS URL you enter. Verify that the target page does not redirect back to the blocked storefront.

Challenge

Matched visitors receive the supported verification path. This action is available on paid plans.

Whole store vs checkout only

Whole store checks every storefront path. Checkout only allows normal browsing and evaluates checkout paths.

Strict mode

Strict mode hides page content until an allow decision arrives. It fails open after a short timeout so a Country Shield outage does not leave the storefront permanently hidden.

Plans and Shopify billing

Open Billing inside Country Shield to compare plans. Shopify hosts plan selection and charge approval. Charges appear on the Shopify invoice, and merchants can upgrade or downgrade without reinstalling the app.

  • Free includes two denylisted countries, a 7-day allowlist trial, and basic blocking.
  • Pro adds unlimited countries, regions, paid actions, analytics, strict mode, and custom messaging.
  • Premium adds ASN/IP rules, Cloudflare sync, and provider-dependent anonymous traffic controls.
VPN, proxy, Tor, and hosting-provider controls remain disabled until the licensed Premium threat database is connected. The merchant app shows the current availability.

Connect Cloudflare on Premium

Cloudflare edge sync is optional. It adds earlier country enforcement before a request reaches Shopify, while the Country Shield theme extension continues to enforce the complete saved policy.

Prerequisite: your store needs an active custom storefront domain in a Cloudflare zone, and that hostname must be proxied through Cloudflare. Your permanent myshopify.com address is not a Cloudflare zone.
1

Confirm the Shopify hostname is proxied

In Cloudflare DNS, use a Proxied CNAME from your custom storefront hostname to shops.myshopify.com. Cloudflare calls this Shopify Orange-to-Orange (O2O) routing. Follow Cloudflare’s Shopify provider guide. Do not enable Cloudflare’s account-wide Always Use HTTPS option for the O2O hostname because it can interfere with Shopify’s certificate validation path.

2

Create the least-privilege token

In Cloudflare, open My Profile → API Tokens → Create Token → Create Custom Token. Use a descriptive name such as Country Shield – example.com. Add exactly these permissions:

  • Zone → Zone → Read
  • Zone → Zone WAF → Edit (called Zone WAF Write in Cloudflare’s API documentation)

Under Zone Resources, choose Include → Specific zone → your storefront domain. Do not choose all zones and do not use the Global API Key. Leave Client IP filtering blank unless Country Shield support has supplied a fixed service IP. Avoid a short token expiration if you want automatic rule sync to continue. Review Cloudflare’s token instructions.

3

Copy the token immediately

Choose Continue to summary → Create Token. Cloudflare shows the token secret once. Copy it directly into a password manager or the Country Shield connection form. Never email it, paste it into support chat, or store it in a shared document.

4

Find the Zone ID

Open the storefront domain in Cloudflare, go to Overview, and locate the API section near the bottom. Copy Zone ID, not Account ID. See Cloudflare’s Zone ID guide.

5

Connect and verify

In Country Shield, open Cloudflare, paste the Zone ID and token, and choose Connect and sync. After it succeeds, Cloudflare should contain a security rule named Country Shield — managed geo block. Find it under Security → Security rules, or Security → WAF → Custom rules in the older dashboard.

What synchronizes to Cloudflare

Country Shield mirrors country allowlist and denylist logic. A Country Shield block becomes a Cloudflare block; Challenge becomes Managed Challenge. Verified search bots remain allowed. Redirect and checkout-only policies pause and remove the edge rule so their exact behavior can continue through the storefront app embed. Regions, ASN, IP/CIDR, VPN, proxy, Tor, and custom messages also remain in the storefront check. Country Shield edits only its own managed rule and leaves your other Cloudflare rules untouched.

Automatic sync and token rotation

Saving protection rules automatically refreshes the connected Cloudflare rule. Sync now forces an immediate refresh. To rotate credentials, disconnect Country Shield first, create and connect a replacement token, verify a successful sync, and then revoke the old token in Cloudflare.

Disconnect safely

Choose Disconnect in Country Shield before revoking the Cloudflare token. Country Shield attempts to remove its managed rule and then deletes the encrypted credential. If the token was already revoked, manually remove the Country Shield rule in Cloudflare.

Troubleshooting

The app says “Not active yet”

Save a ruleset, enable Country Shield under App embeds in the active theme, save the theme, and confirm the setup step in the embedded app.

Shopify asks me to reconnect

The store's rotating offline token may have expired or become invalid. Use the reconnect action and approve the same scopes again.

A paid plan still shows Free

Return from Shopify's hosted plan selection page and wait for verification. If the plan does not update, contact support with the store domain and approximate approval time.

Cloudflare says the token cannot edit the zone

Confirm that the token has both Zone Read and Zone WAF Edit, and that Zone Resources includes the same specific domain whose Zone ID you pasted. Account ID and Zone ID are different.

The Cloudflare rule exists but traffic is unaffected

Confirm the custom Shopify hostname is proxied in Cloudflare DNS. A DNS-only record bypasses the merchant’s Cloudflare security rules. Also confirm that the saved Country Shield policy contains at least one country.

Cloudflare sync stopped after working

The token may have expired, been revoked, or lost access when a Cloudflare user or role changed. Disconnect and reconnect with a new restricted token. If the old token cannot remove the rule, remove the Country Shield rule manually before reconnecting.

The wrong country is detected

Country decisions rely on the visitor's public IP and the current GeoIP database. Corporate networks, mobile carriers, and VPNs can exit in another location.

VPN or Tor controls are unavailable

The Premium anonymous-IP provider database is not currently connected. Country and ASN rules remain available according to plan.