Reference
Routes
Every page and API route the storefront serves, whether it is public or private, and how Locale prefixes apply.
Every address the storefront answers. Public pages can be indexed by search engines and appear in the sitemap. Private pages carry a noindex robots rule, and many also need a signed-in session or a token.
Locale prefixes
Section titled “Locale prefixes”- The default Locale (the first in
STOREFRONT_LOCALES) has no prefix:/shop,/product/soy-candle. - Every other Locale prefixes every page route:
/ar/shop,/ar/product/soy-candle. - With a single Locale, nothing is prefixed and there is no language switcher.
- API routes and the files under Special files are never prefixed.
In the tables below, {slug} and {id} are placeholders.
Shopping
Section titled “Shopping”| Route | Page | Access |
|---|---|---|
/ |
Home, with the sections chosen in HOME_SECTIONS |
Public |
/shop |
All products, with filters and the optional promo banner | Public |
/categories |
Searchable index of all categories | Public |
/category/{slug} |
Category listing, with a strip of sub-categories | Public |
/tag/{slug} |
Tag listing | Public |
/brands |
Brand directory | Public |
/brand/{slug} |
Brand listing | Public |
/product/{slug} |
Product page | Public |
/search?q= |
Search results | Private (noindex) |
/compare |
Product comparison | Private (noindex) |
/cart |
Cart | Private (noindex), cannot be framed |
/checkout |
Checkout, guests allowed | Private (noindex), payment page |
/order-confirmation/{id}?key= |
Thank-you page | Needs the order key; private, payment page, sends no referrer |
Listing pages accept filters in the address, so filtered views can be shared: ?category=, ?tag=, ?brand=, ?minPrice=, ?maxPrice=, ?rating=, ?sale=1, ?stock=1, ?sort=, ?page=, ?q=, ?view=grid or list, and ?cols=2, 3 or 4.
Content
Section titled “Content”| Route | Page | Access |
|---|---|---|
/blog |
Blog index | Public |
/blog/{slug} |
Blog article | Public |
/about-us |
About page, from storefront config | Public |
/contact-us |
Contact details and form | Public |
/faq |
FAQ | Public |
/find-a-store |
Store locations, from storefront code | Public |
/returns-refunds |
Returns and refunds policy | Public; 404 when not set in WordPress |
/shipping-policy |
Shipping policy | Public; 404 when not set |
/privacy-policy |
Privacy policy | Public; 404 when not set |
/terms-and-conditions |
Terms and conditions | Public; 404 when not set |
/cookies-policy |
Cookie policy | Public; 404 when not set |
Sign-in
Section titled “Sign-in”All are private (noindex). A signed-in shopper who opens one is sent on.
| Route | Page |
|---|---|
/login |
Sign in, with Google and Facebook when configured |
/register |
Create an account |
/forgot-password |
Request a password reset link |
/reset-password |
Choose a new password from the emailed link |
/verify-email |
Email verification landing page |
Account
Section titled “Account”All need a signed-in session. Opening one while signed out goes to /login and returns afterwards.
| Route | Page |
|---|---|
/account |
Dashboard |
/account/orders |
Order history |
/account/orders/{id} |
Order details, status tracker and invoice download (the order’s owner only) |
/account/addresses |
Address Book |
/account/addresses/new |
Add an address |
/account/addresses/{id} |
Edit an address |
/account/profile |
Name, phone and profile photo |
/account/security |
Password and connected social accounts |
/account/wishlist |
Wishlist |
/account/stock-alerts |
Back-in-stock alerts (when alerts are switched on in WordPress) |
Email links and editor tools
Section titled “Email links and editor tools”| Route | Page | Access |
|---|---|---|
/stock-notifications/verify?token= |
Confirms a back-in-stock sign-up | Token from the email; private |
/stock-notifications/unsubscribe?token= |
Cancels a back-in-stock alert | Token from the email; private |
/preview/product/{id} |
Product Preview of an unpublished product | Preview session only; blocked in robots.txt |
/preview/unavailable |
Shown when a preview link is spent or expired | Blocked in robots.txt |
/header-preview |
Live target for the WordPress header builder’s preview | Internal; private |
| Any other address | 404 page inside the store’s header and footer | — |
API routes
Section titled “API routes”Used by the storefront’s own pages. They are not a public API and are blocked in robots.txt.
| Route | Purpose |
|---|---|
/api/auth/[...nextauth] |
Auth.js sign-in, sign-out and session |
/api/auth/register |
Create an account |
/api/auth/forgot-password |
Send a reset link |
/api/auth/reset-password |
Set a new password |
/api/auth/resend-verification |
Resend the verification email |
/api/account/avatar |
Upload a profile photo |
/api/account/change-password |
Change the password |
/api/account/set-password |
Set a password on a social-only account |
/api/account/social/{provider} |
Disconnect a social sign-in (DELETE) |
/api/account/compare |
Sync the compare list across devices |
/api/account/orders/{id}/invoice |
Stream an order’s PDF invoice after an ownership check |
/api/catalog/products/{slug} |
Full product data for quick view and compare |
/api/search |
Live search suggestions |
/api/checkout/resume |
Find the order a lost or pending checkout already placed |
/api/newsletter/subscribe |
Newsletter sign-up |
/api/reviews/media |
Upload one review photo or video |
/api/preview/enter?token= |
Start a Product Preview session from a one-time link |
/api/preview/exit |
End the preview session |
Special files
Section titled “Special files”| Route | Purpose |
|---|---|
/sitemap.xml |
Every public page in every Locale, with language alternates. Needs SITE_URL. |
/robots.txt |
Allows all crawlers, including AI crawlers; blocks /api/ and /preview/. Needs SITE_URL. |
/llms.txt |
A Markdown guide to the store for AI assistants. Needs SITE_URL. |
/icon.png |
Fallback favicon. The WordPress Site Icon is used when set. |