Use case for BSS B2B Lock

Add a Request Access Button to Locked Pages

Add a Request access button to locked pages or prices so buyers can apply and you approve or reject each request, with email notices, in BSS B2B Lock.

  • App: BSS B2B Lock
  • Business model: Wholesaler
  • Key feature: Request access lock

Last updated

Reviewed by Hoa Nguyen, Senior Marketer. Last reviewed

BSS B2B Lock message preview for Request access showing Members only and a Request access button
  • 4.9/5 651 reviews of BSS B2B Lock on the Shopify App Store
  • Built for Shopify Badge Shopify gives apps that meet its quality standards
  • 20 languages supported in the app

The problem

Qualified buyers reach a locked page or hidden price and have no way to apply. They leave, or they email your team, which slows the vetting you wanted in the first place.

The outcome

Logged-in visitors see a Request access button and a short form. You review each request in the app, approve or reject it, and the buyer receives an email with the decision.

how it works

How it works

  1. Create the lock

    Create a lock for the page, content or prices you want to protect, using Create my own lock.

  2. Choose Request access

    In Access & Message open User type and choose Request access, visitor request, you approve.

  3. Customize the messages

    Edit the request, pending, rejected, revoked and login prompt messages and tell buyers what to include.

  4. Review requests

    Open Customer Access Requests, turn on email notification, then approve, reject or revoke each request.

  5. Test end to end

    Use a private window and a test account to request access, approve it and confirm the content unlocks.

To add a Request access button to a locked Shopify page or price, create a lock in BSS B2B Lock and choose User type > Request access as the condition. Visitors sign in, click the button, send a short form, and you approve or reject each request from one list. The buyer gets an email with your decision.

This page is for wholesalers and brands that want to vet buyers before showing trade prices, but do not want to hand out passcodes or tag customers by hand. It covers the whole flow, what buyers see at each stage, the plan and account requirements, and the limits you should know before you rely on it.

Who this is for

Request access suits you if:

  • You sell to licensed professionals, resellers or certified partners and want to check each one.
  • Your locked pages or prices currently lead to a dead end, and serious buyers email your team or leave.
  • You do not want to share one passcode that anyone can forward.
  • You prefer a personal yes or no over a registration form that approves automatically.
  • Your buyers already have customer accounts, or you are happy to ask them to create one first.
  • You want a single list of everyone who asked for access, with a status for each.

Why this matters

A plain lock tells visitors “no” without telling them what to do next. Serious buyers email your team or leave, and you lose the chance to vet them in a structured way. Requests that arrive by email get lost between inboxes, and nobody can tell which ones were answered. A request flow keeps every application in one list, with a status, and tells the buyer what is happening.

The cost of a dead end is real for a professional brand. DermaplanePro, a skincare brand that sells to licensed professionals, built its wholesale process around strict buyer qualification, a locked B2B storefront and verified onboarding; read the DermaplanePro case study. The lesson for any brand with a vetted audience is the same: the less you rely on informal email, the faster you can say yes to a good buyer.

Picture a wholesaler of professional hair-care products that only sells to licensed stylists. A salon owner finds a product link in a search result, sees a message that prices are for approved professionals, clicks Request access, adds a line about their salon and waits. The team checks a licence number, approves the request, and the buyer sees prices on the next page load. Nobody had to pass a code around or tag a customer by hand.

What Shopify covers natively, and where an app helps

Shopify’s built-in B2B features, listed on the B2B features by plan page of the Help Center, are about companies, catalogs, payment terms and quantity rules. Hiding prices or pages from visitors until you approve them is not on that list; the pillar guide Shopify B2B makes the same point about hiding prices.

BSS B2B Lock adds a Request access condition to its locks. It works on the Online Store, for pages, content and prices you choose to lock. The access control hub compares it with passcodes, secret links, tags and login-only locks.

How to set it up with BSS B2B Lock

Before you start

Check three things. The BSS B2B Lock app embed is on in your current theme, customer accounts are enabled in Shopify so shoppers can log in, and your store sells through the Online Store channel. If you publish a new theme later, re-enable the app embed so your locks keep working.

1. Create a lock with the Request access condition

Open Locks > Add lock rule, choose Create my own lock, name it and pick what to protect: pages, content or prices. In Access & Message, click the User type chip in Rule 1 and select Request access: visitor request, you approve.

BSS B2B Lock Access and Message step with the User type dropdown open and the option Request access, visitor request, you approve selected
Step 2: choose User type, then Request access, visitor request, you approve.

2. Customize every message

Use the Preview card to edit the messages buyers see: the request message with its button, the pending message, the rejected message, the revoked message and the login prompt. A request message written like an invitation, for example “Wholesale prices are available for registered partners, request access below”, works better than a flat “Access denied”. Say in the message what to include, such as a company name or a short note about the business.

BSS B2B Lock message preview for Request access showing Members only and a Request access button
The request message with the Request access button, editable in the app.

3. Know what the buyer sees

A buyer who is not signed in sees a prompt to sign in first. A signed-in buyer clicks the button and fills in a short form; the email comes from their account, and they add a name and an optional note.

Request access lock seen by a guest: Sign in to continue, Please log in to request access to this content, with a Log in button
A visitor who is not signed in is asked to log in before requesting access.
BSS B2B Lock request form preview with email, full name and an optional message field
The request form: the email comes from the account, the buyer adds a name and an optional note.

After sending the request, the buyer sees the pending message until you decide.

BSS B2B Lock pending message preview: Request submitted, we will notify you once approved
After sending the request the buyer sees a pending message until you decide.

4. Review and decide in Customer Access Requests

Open the access management page and the Customer Access Requests tab, next to Passcode Requests. Turn on Enable email notification and set the address that should receive alerts. Filter by status, or search by name, email or rule. Approve a request with the check mark, reject it with the cross, open the eye icon to read the buyer’s message, or revoke access later. When you approve, the buyer receives an email.

BSS B2B Lock Customer Access Requests tab with status and search filters and an empty request list
The Customer Access Requests tab, where you review, approve and reject requests.

5. Test it end to end

Open the store in a private window and go to a locked page. You should see the login prompt. Sign in with a test customer account, click Request access, check that the pending message appears and that you receive the notification email. Approve the test request in the app, then refresh the storefront. Approval syncs through a queue, so allow a short delay.

Example

Example for illustration only, not a customer result. A hair-care wholesaler locks its prices with a Request access rule. In one week 14 visitors request access. The team opens Customer Access Requests, filters by pending, and reads each note. Ten include a salon name and a licence number that checks out and are approved; three have no business details and are rejected, with a message that invites them to resubmit; one is a retail customer and is ignored for now. The ten approved buyers each receive an email, and prices appear on their next page load. A month later, one buyer closes their salon; the team opens the list and revokes that buyer’s access, which takes effect the next time they load the page.

Request access, registration form, passcode or tag?

The right gate depends on how much you want to vet and how much work you want to do per buyer.

OptionWho decidesNeeds an accountBest for
Request accessYou, per request and per ruleYes, logged inVetting buyers who already have accounts
Registration form with approvalYou, per applicationCreated at approvalOnboarding new wholesale accounts with tags and prices
PasscodeWhoever knows the codeNoA small group you already trust
Customer tagA tag added by you, a form or a ruleYesOngoing access for approved wholesale buyers

Many stores combine two of them. A common pattern is a registration form for new businesses, which tags approved buyers for pricing, plus Request access for a specific locked area, such as a restricted product line, that only some approved buyers should see. Because approval is per rule, one buyer can be approved for the general catalog and still wait for the restricted line.

Writing the messages

Each message is a small piece of onboarding. Keep the request message to two or three lines: who the content is for, what you need from the buyer, and what happens next. In the pending message, say how long you usually take to reply, but only if you can keep that promise. In the rejected message, give a way to reach you, because some rejections are simply missing information. In the revoked message, be neutral and give a contact. You can set a text colour for each message to match your brand and preview every state on desktop and mobile before you save.

Works well with

Key terms: gated catalog, hide price and customer tag.

Limits and common mistakes

  • Buyers must have an account and be logged in. The request is tied to their account. If you want to grant access without a login, use a passcode lock instead.
  • Approval does not add a customer tag. The app keeps its own list of approved, rejected and revoked customers for each rule. If you want a tag for pricing, add it in Shopify, or use registration forms and Auto Tags in BSS B2B Solution.
  • Approval is per rule. A buyer approved for one rule still needs approval for other rules that use Request access. Use one rule for several pages or prices when one approval should cover them.
  • Approval is not instant. It syncs through a queue, so tell your team to allow a short delay.
  • Revoking applies on the next page load. The buyer then sees your revoked message.
  • Big lists. Each rule comfortably supports thousands of approved customers. If you expect 5,000 or more on one rule, contact support first.
  • Locking pages, content or prices needs a paid plan. The Free plan covers the Entire store lock only, so check the plan details in the app before you build a Request access rule.

Setup checklist

  • Enable the BSS B2B Lock app embed and customer accounts in Shopify.
  • Create the lock and choose User type > Request access.
  • Edit the request, pending, rejected, revoked and login messages.
  • Turn on email notification and set the address that receives alerts.
  • Decide who reviews requests and how quickly you will answer.
  • Test with a private window and a test account, from request to approval.
  • Keep your registration page reachable for buyers who have no account yet.
  • Read the Request Access guide for every setting.

Plans and requirements

BSS B2B Lock has a Free plan that covers the Entire store lock and paid plans from $9.99 per month that unlock the page, content and price targets, with a 7-day trial on paid plans. The price steps up with your store’s Shopify plan; see the pricing page. To tag approved buyers and apply wholesale prices, add BSS B2B Solution.

key features

What makes it work

Request access condition

Shoppers sign in, send a short request with a name and optional message, and wait for your decision.

Approve, reject or revoke

Handle each request in the Customer Access Requests tab and change your mind later.

Editable messages

Customize the request, pending, rejected, revoked and login messages.

Email notifications

Get a notification for new requests; buyers get an email when you approve or reject.

Set this up with BSS B2B Lock

Install BSS B2B Lock from the Shopify App Store, then follow the guide to turn this on in your store.

faq

Frequently asked questions

How do I add a request access button to a locked Shopify page?

Create a lock in BSS B2B Lock, choose what to protect, then in Access & Message pick User type and the option Request access. Visitors see a Request access button on the locked content, sign in, send a short form, and you approve or reject the request in the app.

Do buyers need an account to request access?

Yes. Buyers must have a customer account and be logged in, because the request is tied to their account. Visitors who are not logged in see a Sign in to continue prompt first. If you want to grant access without a login, use a passcode lock instead.

Does approving a request add a customer tag?

No. Approval is stored by the app per lock rule, and it does not add a tag to the customer. If you also need a tag, for example for pricing rules, add it in Shopify or use BSS B2B Solution, whose registration forms and Auto Tags rules can tag customers.

Is access granted immediately after I approve?

Approval is synced through a queue, so allow a short delay before the buyer sees the content, and tell your team not to expect it to be instant. The buyer also receives an email with the decision. Test one request end to end before you announce the process.

Does approval unlock all my locks for that buyer?

No. Approval is granted per lock rule. A buyer approved for one rule still needs approval for other rules that use Request access. Use one rule for several pages or prices when you want a single approval to cover them.

Can I remove access after approving someone?

Yes. Find the approved customer in Customer Access Requests and click Revoke. Revoking takes effect the next time the buyer loads the page, and they then see your revoked message. You can customize that message so it tells them how to contact you.

What can a buyer tell me in the request?

The form takes the email from the buyer's account automatically, then asks for a full name and an optional message of up to 500 characters. Use your request message to tell buyers what to include, such as a company name or a short note about their business, so you can decide faster.

Can a rejected buyer ask again?

Yes. A buyer who was rejected can submit a new request, and it appears in your list as pending again. Write your rejected message so it tells them how to contact you, or what to add to a new request, to avoid repeat submissions with no new information.

  • BSS B2B Lock
  • Request Access