Install on Shopify
Route your storefront through your own free Cloudflare — the setup Shopify and Cloudflare support together — then connect Frenemy with one click.
AI shopping agents — ChatGPT, Perplexity, and the rest — increasingly decide what to recommend and buy by reading your storefront. Frenemy shows you every one that visits your store: which are the real agents sending you customers, which are impostors wearing familiar names, and what each one did. On Shopify that runs through your own free Cloudflare in front of your store — the one setup Shopify and Cloudflare officially support together (they call it Orange-to-Orange). Once it’s in place, connecting Frenemy is a single click.
Two honest boundaries: Frenemy is observe-only and fails open — if it ever has a problem, your store serves exactly as before — and it structurally cannot see or touch your checkout or payments, because Cloudflare runs no apps on the checkout path.
- 1Add site
- 2Connect
- 3Verify
- 4Done
Before you start
- Your store uses your own domain (like yourstore.com) — not only the free yourstore.myshopify.com address.
- You can log in wherever that domain was bought (GoDaddy, Namecheap, Squarespace Domains, …) — you’ll change one setting there, once, in step 1.
- No Frenemy account needed yet — you create it in the last step (free, no card, no password: we email you a sign-in link).
- The two screens people worry about — Cloudflare and DNS — have a screenshot on every step, so you can always see you’re in the right place.
Check each step off as you go — your progress saves in this browser, so the DNS wait can't lose your place.
Cloudflare is the free layer that sits in front of your store, and your domain needs to live there. This is the only part that isn’t instant, so it goes first. Already using Cloudflare for your domain? Skip to step 2.
Go to cloudflare.com, click Sign up (choose the Free plan — no card), then Add a domain and type your store’s web address exactly as customers see it — like yourstore.com, no https://. Cloudflare copies your existing settings over, so email and everything else keeps working.
Cloudflare then shows you two addresses that look like ada.ns.cloudflare.com. Log in wherever you bought your domain, find the Nameservers setting, replace what’s there with those two, and save. Cloudflare emails you when it’s ready — usually minutes, sometimes a few hours. Your store keeps running the whole time.
TipBought your domain at Cloudflare, or already on Cloudflare? There’s nothing to change here — skip straight to step 2.
Now tell Shopify to use that domain. In your Shopify admin, go to Settings → Domains, click Connect existing domain, and type your domain.
Choose Connect automatically. Shopify works directly with Cloudflare: a Cloudflare screen pops up asking you to authorize a one-time DNS setup — click Authorize. It’s a single approval and doesn’t let Shopify make any future changes.
Shopify sets everything up for you and provisions your security certificate — about five minutes. When the domain shows Connected with a green checkmark, this step is done.
Choose Connect automatically — Shopify handles the DNS records for you. One switch turns the plain setup into the supported one. In Cloudflare, open your domain → DNS → Records — you’ll see the records Shopify just created.
Delete the two records named after your bare domain with type A and AAAA (their values look like 23.227.38.65). Leave the long dns-verification record alone.
In their place, click Add record: type CNAME, name @, target shops.myshopify.com, and make sure Proxy status shows the orange cloud (Proxied). Cloudflare spells the result back to you — “your domain is an alias of shops.myshopify.com and has its traffic proxied through Cloudflare.” When you see that sentence, it’s exactly right. Save.
Do the same for the www record: click Edit, set it to CNAME → shops.myshopify.com, orange cloud (Proxied), Save. Both records now show the orange cloud — that’s Orange-to-Orange, live. Open your store in a new tab to confirm it loads as normal, padlock and all.
Watch outAlways use a CNAME to shops.myshopify.com — never an A record with an IP address. The supported setup only engages on the proxied CNAME.
Watch outDon’t turn on Cloudflare’s “Always Use HTTPS” (under SSL/TLS → Edge Certificates). It interferes with how Shopify renews your security certificate — and Shopify already sends shoppers to https on its own.
TipAnything look off? Flip both records’ orange cloud back to grey (“DNS only”) and you’re back to the old setup within minutes. Nothing here is permanent.
Before: delete the A and AAAA records named after your bare domain. Quick confidence check: run the free store check at frenemy.dev/store-check on your domain. Every door that read open before should still read open — that’s your proof the new setup isn’t turning away the AI shopping agents that recommend products.
One Cloudflare setting to glance at, under Security → Bots: leave Bot Fight Mode off (it’s off by default). We measured this on a live store — turning the default Bot Fight Mode on did not close any of the public doors over our test window. Stricter, custom bot rules genuinely can, though, and blanket bot-blocking is the opposite of what you’re doing here. Rule of thumb: after any security change, re-run the store check.
The hard part is behind you. Go to app.frenemy.dev and enter your email — we send you a sign-in link, so there’s no password to invent and no card to enter. Your free trial doesn’t start until Frenemy actually sees your traffic working.
On “Add your site”, type your domain. Frenemy recognizes the setup you just built and shows a Connect Cloudflare button. Click it and approve on Cloudflare’s own screen (use the same Cloudflare account from step 1 — we never see your password).
Review the short list of what Frenemy will add — one small observe-only worker, its key, and a route — then click Create. Click Send a test hit, and within seconds the wizard flips to Connected. From that moment every automated visitor to your storefront is verified, classified, and counted. That’s the whole install.
Frenemy recognizes your setup — click Connect Cloudflare.
What this install can see
Every number in your dashboard traces to what this install can actually observe — nothing is estimated or filled in.
Every request that reaches your storefront through Cloudflare — product pages, collections, static files, and the AI agents reading them — each with a verified identity, because Cloudflare hands Frenemy the true visitor IP.
Your checkout and payment pages: Cloudflare runs no apps on the checkout path, so Frenemy — like every app — structurally can’t see it, and we confirmed a live order flows through Shopify untouched. Traffic on the free .myshopify.com address isn’t seen either — only your real domain.
Troubleshooting Shopify
Is putting Cloudflare in front of Shopify actually supported?
Yes — this specific setup (a proxied CNAME to shops.myshopify.com) is recognized by both companies: Cloudflare documents it as Orange-to-Orange. What ISN’T supported is pointing other proxies or bare IP addresses at Shopify — stick to the proxied CNAME exactly as written above.
Will this break my checkout?
No — checkout is deliberately outside the setup. Cloudflare runs no apps on the checkout path, and Shopify keeps serving it exactly as before. We placed a live test order through this exact setup before publishing this guide. Want your own proof? Add something to your cart and walk to the payment screen — you’ll see zero difference.
My store stopped loading (or shows a certificate warning) after the change.
First: nothing is permanent. Flip both DNS records’ Proxy status back to “DNS only” and your store returns to the old setup within minutes.
Usually it’s just propagation — give it up to an hour. If a certificate warning persists, check that “Always Use HTTPS” is OFF in Cloudflare (SSL/TLS → Edge Certificates); it blocks the path Shopify uses to renew certificates. Email support@frenemy.dev and a human will look with you.
The store check shows doors closed after I moved to Cloudflare.
A Cloudflare security setting is challenging automated visitors. Check Security → Bots (Bot Fight Mode off) and any firewall rules you’ve added, then re-run the store check — it reads your store’s doors exactly the way agents do.
More fixes in Troubleshooting, or email support@frenemy.dev and a human will help.