Blog·September 9, 2026

How to block Honey and coupon extensions on Shopify

Shopify has no setting for it. What works against Honey, Coupert and Capital One Shopping, what doesn't, and the free fix for PromoLock stores.

Watch a checkout with Honey installed and you’ll see the problem in about four seconds. The shopper reaches the payment step, a small panel slides in, and the extension runs every code it holds for your store until one sticks. Your influencer’s 20%. The abandoned-cart code from March. The VIP code you gave to forty people. The shopper didn’t hunt for any of them. They clicked “Apply coupons” and got the best one.

Merchants have been asking how to stop this on the Shopify Community boards for years, and the thread is still active because the answer hasn’t changed. Shopify has no setting for it. There’s nothing in the admin that says “ignore browser extensions,” and there never has been.

So this is a guide to what you can do instead, starting with the parts that don’t need an app.

What Shopify gives you

You can’t block the extension, but you can change what it finds. Four native settings help, in rough order of how often they’re enough.

Deactivate the code. Obvious, and still the right first move for a code that has no business being public anymore. The abandoned-cart code from March should have expired in April.

Expiry dates and usage limits. A code that dies in two weeks or after 200 uses is a smaller prize. Extensions only hold codes that keep working, so short-lived codes fall out of their pool on their own.

Customer eligibility. Restricting a code to specific customers or a segment makes it fail for anyone else, extension or not. Good for a VIP list of forty. Useless for a public campaign, which is exactly where extensions do the most damage.

Automatic discounts. No code means nothing to harvest. If a promotion doesn’t need attribution (nobody is being paid per redemption), an automatic discount is the cleanest answer there is, and plenty of stores that ask about blocking Honey really just need this.

Where it runs out: anything with a shareable code attached to a person or a campaign. Influencer codes, referral codes, the welcome code in your popup. Those need to stay typeable, and anything typeable ends up in an extension.

What doesn’t work

Two ideas come up in every forum thread, and both cost time you won’t get back.

Asking Honey to remove your store. Honey does take removal requests, and some merchants report success. Others report months of nothing. Even a successful removal covers one extension, while Coupert, Capital One Shopping, Rakuten and the rest keep doing the same thing, and the codes themselves stay published on the coupon sites they were harvested from. One merchant in the Shopify thread reportedly got delisted by publishing a run of joke codes aimed at Honey. Funny, and not a plan.

Theme code that detects extensions. You’ll find snippets that sniff for Honey’s script and hide the discount field. They break when the extension updates, and there’s a bigger problem. On Shopify, the checkout page isn’t your theme. Your theme’s JavaScript doesn’t run there, and checkout is where the extension applies the code. A detector living in the theme can see the extension on your product pages and do nothing about what happens two clicks later.

That second point is the whole reason this needs to work differently.

Blocking at checkout, not in the theme

LeakHunt is a second app from the PromoLock team, and PromoLock customers get it at no charge. Its Extension Guard does the thing the theme snippets can’t. The detection still happens on the storefront, where Honey, Coupert, RetailMeNot, Capital One Shopping, Rakuten, Klarna, Karma, Slickdeals and the rest of the coupon extensions are recognized. But the decision happens inside Shopify’s checkout. When a shopper with one of those extensions reaches checkout, your leaked codes are rejected for that shopper. Every other shopper checks out exactly as before.

Two design choices matter here.

It blocks leaked codes, not all codes. LeakHunt’s Leak Radar reads the big coupon sites for codes attributed to your store and checks each one against your store. Only the ones that exist and still work make the list, and that list is what Extension Guard rejects. A code you marked Intentional (your affiliate’s, or the one printed on your packaging) or added to the Whitelist is never touched, so a legitimate shopper who happens to run Honey can still use the code you meant them to use.

And it errs toward the sale. If anything about the check can’t complete, the code goes through. The worst case is one leaked discount, never a lost order.

Setup is one switch in your theme editor (LeakHunt’s app embed, no code to paste), then the Extension Guard switch on the LeakHunt dashboard. After that, the card shows Orders protected with a breakdown by extension, which is also the first time most merchants find out how much of their traffic runs one.

Two tools, and the choice is yours

Leak Radar and Extension Guard answer different questions. Leak Radar answers “which of my codes are out there and still working?” and gives you a Disable for the ones that shouldn’t be.

Extension Guard is for a code you want to keep live. Plenty of merchants are fine with the code working, whoever uses it. What they mind is the shopper who wasn’t looking for it and gets it anyway, because an extension in their browser applies every working code it knows about. Extension Guard draws the line at the extension: a shopper running one is turned away from your leaked codes at checkout, and every shopper without one is unaffected.

So the decision is per code, and it’s yours. Disable it. Keep it live but out of the extensions’ reach. Or mark it Intentional and let it run everywhere, extensions included.

Choosing your route

Your situation Do this
The code shouldn’t be live at all Deactivate it in Shopify. Done.
Promotion needs no code Switch to an automatic discount
Small private list Customer eligibility, plus an expiry
Public campaign or influencer code Keep the code live and let Extension Guard turn away shoppers running a coupon extension. Mark it Intentional only if those shoppers should get it too
You want to stop the cycle Give each recipient their own single-use code from a bulk set, so a leak costs you one order, not a campaign

Whatever you pick, test it with the extension installed. Add Honey to a spare browser, put a leaked code through a real checkout, and watch what happens on the discount line. That’s the only test that counts.

Loss calculator

Estimate your unintended loss.

Four quick questions. Planned promotions never count.

?$3.5M
Which of these are true for you?
?
?
?
?