> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Whether the storefront is behind Shopify's password page

> Returns a bare boolean: true when the online store is password-protected, so shopper-facing previews cannot load. Asks Shopify live; a 502 means Shopify could not be asked (dead token, frozen shop, no config), so the answer is unknown, not false. Read-only.



## OpenAPI

````yaml /api-reference/openapi/lite.json get /merchants/{merchant_id}/storefront-password-protected
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /merchants/{merchant_id}/storefront-password-protected:
    get:
      summary: Whether the storefront is behind Shopify's password page
      description: >-
        Returns a bare boolean: true when the online store is
        password-protected, so shopper-facing previews cannot load. Asks Shopify
        live; a 502 means Shopify could not be asked (dead token, frozen shop,
        no config), so the answer is unknown, not false. Read-only.
      operationId: isStorefrontPasswordProtected
      parameters:
        - schema:
            type: string
            description: Lite merchant id, e.g. `shopify-<shop id>`.
          required: true
          description: Lite merchant id, e.g. `shopify-<shop id>`.
          name: merchant_id
          in: path
      responses:
        '200':
          description: true = password-protected.
          content:
            application/json:
              schema:
                type: boolean
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: Authenticated, but this identity may not call the API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '404':
          description: Merchant not found for this caller.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '502':
          description: Shopify could not be asked, so protection is unknown.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````