Sneaker drops, gift-card abuse, and fake account creation all hit Shopify stores from automated clients. Adding device intelligence gives your storefront a stable visitor ID and bot score, so you can flag the scripts hammering your cart and account pages.
This guide adds Prynt to a Shopify theme using Liquid and the CDN build, then verifies events from a backend that holds your secret key. Shopify limits how much you can customize the hosted checkout on most plans, so the highest-leverage targets are account creation, login, and cart interactions, which the theme controls directly.
Load the agent in your theme
Drop the CDN script into theme.liquid so it loads on every storefront page. No build step required.
{% comment %} layout/theme.liquid {% endcomment %}
<script src="https://api.pryntid.com/cdn/prynt.umd.js"></script>
<script>
window.pryntReady = Prynt.load({
apiKey: "{{ settings.prynt_public_key }}",
endpoint: "https://api.pryntid.com"
})
</script>
Store the public key in a theme setting so you never hardcode it across templates.
Capture a visitor ID on key forms
Account creation and login are the highest-value targets. Attach the event ID when the customer submits.
<form action="/account" method="post" id="register">
<input name="customer[email]" type="email">
<input type="hidden" name="prynt_id" id="prynt_id">
<button>Create account</button>
</form>
<script>
const agent = await window.pryntReady
document.querySelector('#register').addEventListener('submit', async () => {
const result = await agent.identify()
document.querySelector('#prynt_id').value = result.requestId
})
</script>
Because Shopify’s native form posts go to Shopify, mirror the event ID to your own endpoint or app webhook so you can verify it.
Verify from your backend
A Shopify app or standalone backend verifies the event with your secret key. This is the only place a decision belongs.
const res = await fetch(
`https://api.pryntid.com/v1/events/${pryntId}`,
{ headers: { Authorization: `Bearer ${process.env.PRYNT_SECRET}` } }
)
const event = await res.json()
if (event.bot.result === 'automated' || event.proxy.isProxy) {
flagOrder(pryntId) // review, tag, or throttle
}
Storing visitorId against the customer lets you catch one device farming many accounts for gift-card or coupon abuse. The signal set is described in the bot detection guide.
A practical pattern for stores is to verify asynchronously against Shopify’s order and customer webhooks. When an order or new account event fires, your app looks up the matching Prynt event, checks the score and proxy flags, and applies a tag like review or high-risk through the Admin API. That keeps the storefront fast while still giving your fulfillment team a clear queue of orders worth a second look, without ever blocking a legitimate shopper mid-purchase.
Guard forms directly
Let Form Shield watch the element for scripted fills that produce a clean POST.
agent.protectForm(document.querySelector('#register'), {
autoGuard: true,
expectedScripts: ['latin']
})
expectedScripts flags submissions in unexpected writing systems, useful against bulk account bots. Pair it with backend verification for both a behavioral and an identity signal.
Use signals for tagging, not just blocking
On Shopify you often cannot block the native checkout, so lean on tagging and review: flag high-risk orders, throttle suspicious accounts, and feed the visitor ID into your fraud rules. Prynt is a managed cloud service, so geolocation, proxy, VPN, and bot scoring arrive with no infrastructure to run, and the free tier covers a growing store’s traffic.
Start small: protect account creation and login first, since those are where most abuse originates, then extend tagging to orders once the pipeline is proven. Add the script, wire a backend endpoint, and check the pricing and free plan to start defending your Shopify store against automated abuse.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.