Skip to content
weLabsweLabsStorefront Playbook
Live demoQuickstart

Features

Accounts and sign in

Email and social sign-in, verified registration, secure sessions and a customer dashboard with orders, addresses, profile and security in one place.

Customer accounts live in WordPress, so every shopper who registers on the storefront is an ordinary WooCommerce customer. The storefront gives them a modern way in — email or one tap with Google or Facebook — and a dashboard they will actually use: orders, invoices, saved addresses, wishlist, stock alerts and account security.

Where it shows
/login, /register, /forgot-password, /verify-email and everything under /account
Configure in
StoreFront → Settings → Authentication (Social Login); account emails under WooCommerce → Settings → Emails
Requires
The Companion plugin with its sign-in secret in wp-config.php; WooCommerce REST API keys on the storefront for orders and dashboard figures
Try it in Demo Mode
Sign in with demo@retail.store / demo1234
  • Email and password, with Remember me: ticked, the session lasts 30 days; unticked, it ends after 24 hours.
  • Google and Facebook sign-in on the login and register pages. Only the providers you have set up appear.
  • The last method used is remembered, so a returning shopper sees the button they used before in its usual place.
  • Registration asks for first and last name, email, a password with confirmation, and consent to your terms and privacy policy. A verification email follows; the account can sign in once the email is confirmed, and the shopper can ask for a new link.
  • Forgot password sends a reset link that opens on your storefront, with a clear message if the link has expired.
  • Pick up where they left off. Opening an account page while signed out leads to sign-in and then straight back.
  • Sessions renew quietly in the background, so shoppers are not signed out in the middle of a purchase.
  • Signing out asks for confirmation and also ends the session on the WordPress side.
  • If a stolen session is ever replayed, WordPress signs that customer out everywhere and emails them a security alert.
  • Store staff — administrators and shop managers — cannot use social sign-in and must use their password.

Everything a customer needs sits under /account:

Page What customers can do
Dashboard See a welcome with their member-since date, their total orders, orders in progress, total spent and wishlist count, recent orders, quick actions to track an order, buy again, manage addresses or edit their profile, their account details and saved addresses at a glance, and a Need help? card with a Contact support button to your contact page.
Orders Browse orders by status, open the details and status tracker, buy again and download invoices — see Orders and invoices.
Addresses Keep up to ten addresses, labelled Home, Office, Other or a name of their own; choose a default billing and a default shipping address; edit or delete. Duplicates are refused, and only countries you sell to are accepted.
Profile Upload a profile photo (JPEG or PNG, up to 5 MB) and change first, last and display name and phone. The email address is shown but cannot be changed here.
Security Change the password, which signs out other devices; set a password on an account created with Google or Facebook; see connected social accounts and disconnect them.
Wishlist See and manage saved products — see Wishlist and compare.
Stock alerts See back-in-stock alerts and cancel them — see Stock alerts. Shown only when stock alerts are switched on.

The default billing and shipping addresses are copied into the customer’s WooCommerce record, so checkout and wp-admin always agree. A social account can be disconnected only while another way to sign in remains, so nobody locks themselves out.

Sign-in, registration and password resets are handled by the Companion plugin against your WordPress users, and the storefront keeps the shopper’s session in a secure cookie. Social sign-in is verified by WordPress: the storefront only learns which providers are available and their public IDs.

A store-branded Google button. Setup needs only a Google Client ID — no client secret — and the storefront’s login address registered with Google.

  1. Add the sign-in secret to wp-config.php and set the Storefront URL, so verification and reset emails link to the storefront — see Sign-in and security and Connect the storefront.
  2. Paste your Google Client ID and Facebook App ID and Secret under StoreFront → Settings → Authentication → Social Login. The built-in setup guides walk through Google Cloud and the Meta developer dashboard; buttons appear without a redeploy.
  3. Add the WooCommerce REST API keys to the storefront so the dashboard can show orders and totals — see Connect to WooCommerce.
  • Sign-in with Google and Facebook is available today. Other providers are on the roadmap.
  • Accounts without a confirmed email cannot sign in until they follow the verification link.
  • Account pages, sign-in pages and email links are kept out of search engines.
  • Customers’ address books are included in WordPress’s personal-data export and erase tools.
Storefront Playbook · Built by weLabsFeaturesFAQTalk to us