GhostClick · Guide

Password-Protected & Login-Gated Stores

How GhostClick handles storefront passwords, login walls, and development stores.

Why This Comes Up

Not every store is open to the public. A new Shopify store might still have Password protection switched on in Online Store → Preferences. A subscription or B2B site might require a customer login before you can browse or check out. Either way, an AI agent hitting that wall looks exactly like a real visitor would — it needs the same information a customer would need.

How GhostClick Detects It

When you enter a store URL for a new audit or journey, GhostClick fetches the page and checks whether it looks like a Shopify password page or a login screen before the run starts. If it does, it automatically adds a question to the setup form instead of letting the audit fail partway through:

Access question

What is the store password?

e.g. secret123

Storefront password

If Online Store → Preferences has a password set, GhostClick asks "What is the store password?". Enter the same password your customers would use. The agent enters it on your behalf as the very first step of the run, then continues with the journey as normal.

Login-gated stores

If the destination looks like a login page rather than a password page, GhostClick instead asks "What are the login credentials? (email and password)". Use a test account rather than a real customer's — the agent will type whatever you provide into the login form.

Note

Only provide credentials for a test or staff account you control, and only for a site you own or are authorised to test. See Terms of service for the acceptable-use rules around this.

These Answers Stick Around

Access questions are kept separate from the goal-driven clarifying questions GhostClick may also ask (for example, to disambiguate an unusual journey description). If you edit your journey goal later and new clarifying questions appear, your stored store password or login answer is preserved rather than being cleared out — you won't be asked twice for the same store.

Development and Staff Stores

Shopify development stores are usually also password-protected by default. The same flow applies: GhostClick detects the password page and asks for the storefront password (found in Online Store → Preferences in that store's admin). Development stores installed through Shopify also see a free developer plan automatically, so you can test the integration itself without needing an active subscription.

What Gets Stored

The password or credentials you provide are saved with the journey so scheduled and repeat runs don't stop and ask again. Treat them like any other credential in your account — anyone with access to your GhostClick journey can see and reuse them. If a storefront password changes, update the answer on the journey (or from the audit setup form) the next time you run it.