Install on Shopify
Point your domain through your own free Cloudflare account — a setup Shopify and Cloudflare support together — then Frenemy connects with one click.
Shopify runs your store's servers, so nothing installs inside Shopify itself. Instead, your domain gets a free Cloudflare account in front of it — a setup Shopify and Cloudflare officially support together (Cloudflare shows a little Shopify logo when it's active). Once that's in place, Frenemy connects with one click, and every automated visitor to your storefront is verified and counted.
Two honest boundaries up front: Frenemy is observe-only to start and fails open — if it ever has a problem, your store serves exactly as before. And Cloudflare does not allow ANY apps (ours included) to run on your checkout pages — Frenemy watches your storefront and structurally cannot touch checkout or payments. We verified both on a live store before publishing this guide.
- 1Add site
- 2Connect
- 3Verify
- 4Done
Before you start
- Your store uses your own domain (like example.com) — not only the free yourstore.myshopify.com address.
- You can log in wherever that domain was bought (GoDaddy, Namecheap, Squarespace Domains, …). You'll change one setting there, once.
- No Frenemy account needed yet — you'll create it in step 4 (free, no card, no password — we email you a sign-in link).
- Already use Cloudflare for this domain? Skip straight to step 2 — you're a few clicks from done.
Check each step off as you go — your progress is saved in this browser, so the DNS wait can't lose your place.
- 1
Put your domain on a free Cloudflare account
Go to cloudflare.com and click Sign up — the Free plan, no card needed. (If you have a Cloudflare account already, just sign in.)
Click Add a domain, type your store's domain exactly as customers see it — example.com, no https:// — and pick the Free plan when asked. Cloudflare automatically copies over your existing DNS records, so email and everything else keeps working; glance over the imported list and continue.
Cloudflare now shows you two nameserver addresses (they look like ada.ns.cloudflare.com). Log in at your domain registrar — the company you bought the domain from — find the DNS or Nameservers setting for your domain, replace what's there with those two addresses, and save.
Back in Cloudflare, click Check nameservers. This wait is the slow part: a few minutes to a few hours. Cloudflare emails you when the domain shows Active — that's your cue to continue. Your store keeps running normally the whole time.
TipBrand-new store whose domain isn't connected to Shopify yet? Do Shopify's automatic connect first (Shopify admin → Settings → Domains → Connect existing domain → Connect automatically). It verifies the domain and sets up your store's security certificate in about 5 minutes — and Shopify currently credits you $20 for connecting a custom domain.
- 2
Switch the domain to the supported proxied setup
In Cloudflare, open your domain → DNS → Records. You're replacing the old “point at Shopify's server address” records with the one supported “proxied alias” record.
Delete the A record for your bare domain that points to Shopify's address (it looks like 23.227.38.65), and the AAAA record for the bare domain if there is one. Leave everything else alone — especially any record whose name is a long code pointing at dns-verification.shopify.com.
Click Add record: Type CNAME · Name @ · Target shops.myshopify.com · and make sure Proxy status shows the ORANGE cloud (Proxied). Save. The dialog describes the result in plain English — “your domain is an alias of shops.myshopify.com and has its traffic proxied through Cloudflare.” When it says that, you've got it exactly right.
Find the www record, click Edit, set it the same way: CNAME to shops.myshopify.com, Proxied (orange). Save. (No www record? Add one.)
Within a few minutes, both records show a small Shopify logo next to them. That logo is Shopify and Cloudflare confirming they recognize this setup — they call it Orange-to-Orange. Now open your store in a new tab: it should load exactly as before, padlock and all. In Shopify admin, Settings → Domains still says Connected.
Watch outUse a CNAME to shops.myshopify.com — never an A record with an IP address. The Shopify logo (and the supported setup) only engages on the proxied CNAME.
Watch outDo NOT turn on Cloudflare's “Always Use HTTPS” setting (under SSL/TLS → Edge Certificates). It interferes with how Shopify renews your store's security certificate — and Shopify already sends shoppers to https on its own.
TipAnything look wrong? Flip both records' Proxy status back to “DNS only” and your store is back on the old setup within minutes — nothing is irreversible here.
- 3
Check your store's agent doors survived the move
Run the free store check on your domain: frenemy.dev/store-check. Every door that was open before should still read open — that's your proof the new setup isn't turning away the AI shopping agents that recommend products.
One setting to confirm while you're in Cloudflare: Security → Bots — leave Bot Fight Mode OFF (it's off by default). In our live test, turning it on didn't close the public doors — but stricter bot rules and custom firewall settings genuinely do (we've measured stores where they turn away every agent), and blanket bot-blocking is the opposite of what you're building here. Once Frenemy is connected you'll SEE each agent, verified, and can make deliberate choices instead of blanket ones. Golden rule: after ANY security change, re-run the store check.
- 4
Create your free Frenemy account and connect
Go to app.frenemy.dev and type your email address. We email you a sign-in link — click it and you're in. No password to invent, no card, and your free trial doesn't start until Frenemy actually sees your traffic working.
On “Add your site”, type your store's domain and click Continue. Frenemy detects the setup you just built: “your Shopify store runs behind your own Cloudflare — the supported setup.”
Click Connect Cloudflare and approve on Cloudflare's own screen (log in with the same Cloudflare account from step 1 — we never see your password). Then review exactly what will be created — one small observer Worker, its secret key, and the route for your domain; we only ever ADD things — and click Create — I understand what's being added.
Click Send a test hit. Within a few seconds the wizard flips to Connected — and from that moment, every automated visitor to your storefront is verified, classified, and counted. That's the whole install.
Connect your Cloudflare account
Connect CloudflareYou’ll approve Frenemy on Cloudflare’s own screen — we never see your password. We use the grant once to set up this one site, then release it.
Prefer not to grant account-wide access? Paste a scoped Cloudflare API token instead
Illustration — the one-click Cloudflare connect.
What this install can see
Every number in your dashboard traces to what this install can actually observe — nothing is estimated or filled in.
Every request that reaches your storefront through your Cloudflare — product pages, collections, static files, and the AI agents reading them — with verified identities, because Cloudflare hands Frenemy the true client IP.
Your checkout and payment pages: Cloudflare blocks all apps (Frenemy included) from running on the checkout path — we verified on a live store that checkout flows through Shopify untouched. Traffic on the free .myshopify.com address isn't seen either (only your real domain).
Troubleshooting Shopify
Is putting Cloudflare in front of Shopify actually supported?
Yes — this specific setup (a proxied CNAME to shops.myshopify.com) is recognized by both companies: Cloudflare documents it as Orange-to-Orange and shows a Shopify logo on the DNS record when it's active. What ISN'T supported is pointing other proxies or bare IP addresses at Shopify — stick to the proxied CNAME exactly as written above.
Will this break my checkout?
No — checkout is deliberately outside the setup. Cloudflare blocks apps from running on the checkout path, and Shopify keeps serving it exactly as before. We placed a live test order through this exact setup before publishing this guide. If you want your own proof, add something to your cart and walk to the payment screen — you'll see zero difference.
My store stopped loading (or shows a certificate warning) after the change.
First: don't worry, nothing is permanent. Flip both DNS records' Proxy status back to “DNS only” and your store returns to the old setup within minutes.
Usually it's just propagation — give it up to an hour. If a certificate warning persists, check that “Always Use HTTPS” is OFF in Cloudflare (SSL/TLS → Edge Certificates); it blocks the path Shopify uses to renew certificates. Email support@frenemy.dev and a human will look with you.
The store check shows doors closed after I moved to Cloudflare.
A Cloudflare security setting is challenging automated visitors. Check Security → Bots (Bot Fight Mode OFF) and any firewall rules you've added, then re-run the store check — it reads your store's doors exactly the way agents do.
I got stuck in Frenemy before doing the Cloudflare setup.
If you typed your domain into Frenemy before your Cloudflare setup was live, it will have told you Shopify needs this guide. Finish steps 1–3, then just enter your domain again — nothing is lost, and the one-click connect picks up from there.
More fixes in Troubleshooting, or email support@frenemy.dev and a human will help.