Skip to content
weLabsweLabsStorefront Playbook
Live demoQuickstart

Reference

Routes

Every page and API route the storefront serves, whether it is public or private, and how Locale prefixes apply.

Every address the storefront answers. Public pages can be indexed by search engines and appear in the sitemap. Private pages carry a noindex robots rule, and many also need a signed-in session or a token.

  • The default Locale (the first in STOREFRONT_LOCALES) has no prefix: /shop, /product/soy-candle.
  • Every other Locale prefixes every page route: /ar/shop, /ar/product/soy-candle.
  • With a single Locale, nothing is prefixed and there is no language switcher.
  • API routes and the files under Special files are never prefixed.

In the tables below, {slug} and {id} are placeholders.

Route Page Access
/ Home, with the sections chosen in HOME_SECTIONS Public
/shop All products, with filters and the optional promo banner Public
/categories Searchable index of all categories Public
/category/{slug} Category listing, with a strip of sub-categories Public
/tag/{slug} Tag listing Public
/brands Brand directory Public
/brand/{slug} Brand listing Public
/product/{slug} Product page Public
/search?q= Search results Private (noindex)
/compare Product comparison Private (noindex)
/cart Cart Private (noindex), cannot be framed
/checkout Checkout, guests allowed Private (noindex), payment page
/order-confirmation/{id}?key= Thank-you page Needs the order key; private, payment page, sends no referrer

Listing pages accept filters in the address, so filtered views can be shared: ?category=, ?tag=, ?brand=, ?minPrice=, ?maxPrice=, ?rating=, ?sale=1, ?stock=1, ?sort=, ?page=, ?q=, ?view=grid or list, and ?cols=2, 3 or 4.

Route Page Access
/blog Blog index Public
/blog/{slug} Blog article Public
/about-us About page, from storefront config Public
/contact-us Contact details and form Public
/faq FAQ Public
/find-a-store Store locations, from storefront code Public
/returns-refunds Returns and refunds policy Public; 404 when not set in WordPress
/shipping-policy Shipping policy Public; 404 when not set
/privacy-policy Privacy policy Public; 404 when not set
/terms-and-conditions Terms and conditions Public; 404 when not set
/cookies-policy Cookie policy Public; 404 when not set

All are private (noindex). A signed-in shopper who opens one is sent on.

Route Page
/login Sign in, with Google and Facebook when configured
/register Create an account
/forgot-password Request a password reset link
/reset-password Choose a new password from the emailed link
/verify-email Email verification landing page

All need a signed-in session. Opening one while signed out goes to /login and returns afterwards.

Route Page
/account Dashboard
/account/orders Order history
/account/orders/{id} Order details, status tracker and invoice download (the order’s owner only)
/account/addresses Address Book
/account/addresses/new Add an address
/account/addresses/{id} Edit an address
/account/profile Name, phone and profile photo
/account/security Password and connected social accounts
/account/wishlist Wishlist
/account/stock-alerts Back-in-stock alerts (when alerts are switched on in WordPress)
Route Page Access
/stock-notifications/verify?token= Confirms a back-in-stock sign-up Token from the email; private
/stock-notifications/unsubscribe?token= Cancels a back-in-stock alert Token from the email; private
/preview/product/{id} Product Preview of an unpublished product Preview session only; blocked in robots.txt
/preview/unavailable Shown when a preview link is spent or expired Blocked in robots.txt
/header-preview Live target for the WordPress header builder’s preview Internal; private
Any other address 404 page inside the store’s header and footer —

Used by the storefront’s own pages. They are not a public API and are blocked in robots.txt.

Route Purpose
/api/auth/[...nextauth] Auth.js sign-in, sign-out and session
/api/auth/register Create an account
/api/auth/forgot-password Send a reset link
/api/auth/reset-password Set a new password
/api/auth/resend-verification Resend the verification email
/api/account/avatar Upload a profile photo
/api/account/change-password Change the password
/api/account/set-password Set a password on a social-only account
/api/account/social/{provider} Disconnect a social sign-in (DELETE)
/api/account/compare Sync the compare list across devices
/api/account/orders/{id}/invoice Stream an order’s PDF invoice after an ownership check
/api/catalog/products/{slug} Full product data for quick view and compare
/api/search Live search suggestions
/api/checkout/resume Find the order a lost or pending checkout already placed
/api/newsletter/subscribe Newsletter sign-up
/api/reviews/media Upload one review photo or video
/api/preview/enter?token= Start a Product Preview session from a one-time link
/api/preview/exit End the preview session
Route Purpose
/sitemap.xml Every public page in every Locale, with language alternates. Needs SITE_URL.
/robots.txt Allows all crawlers, including AI crawlers; blocks /api/ and /preview/. Needs SITE_URL.
/llms.txt A Markdown guide to the store for AI assistants. Needs SITE_URL.
/icon.png Fallback favicon. The WordPress Site Icon is used when set.
Storefront Playbook · Built by weLabsFeaturesFAQTalk to us