Enable the storefront serial check
Publish a privacy-safe serial authenticity checker and verify its genuine, invalid, and neutral states.
Public Lookup gives buyers a storefront page where they can check a serial without seeing the linked order, customer, or internal unit history.
What you'll accomplish
- Review whether your serial format is safe for public lookup.
- Enable the signed storefront page.
- Verify genuine, invalid, unknown, and unavailable results before linking it publicly.
Requirements
- Public Lookup must be included in your plan.
- The commerce integration must support the signed storefront proxy.
- Active serial pools should include enough unpredictable entropy to resist enumeration.
- Decide which support email address or URL buyers should see after a lookup.
Enable the checker
- Open Settings → Public Lookup.
- Review any predictable-pattern warning. A sequence-only pattern such as
PRODUCT-{SEQ:6}should not be published broadly; add a sufficiently long random segment to new generation patterns. - Reconnect the store if Serial Trail reports that the app-proxy permission is missing.
- Enable Public serial lookup.
- Enter an optional merchant support email address or HTTPS support URL.
- Save the settings.
- Copy the generated storefront URL and open it in a private browser session.
Verify every public state
Test only synthetic values:
- A genuine active serial should show the product details allowed by the public response.
- A voided serial should be marked invalid.
- An unknown value should receive a neutral result that does not confirm whether nearby serials exist.
- Disabling Public Lookup should immediately return an unavailable state.
The page never exposes order references, customer information, assignment dates, internal lifecycle history, or recall membership unless the buyer uses the separate recall check with a case reference.
What success looks like
- Settings show Public Lookup as enabled.
- The storefront URL opens in the active theme on desktop and mobile.
- Genuine and invalid synthetic values return the expected state.
- Unknown values do not reveal registry details.
- The 30-day counters update without storing buyer identity.
Troubleshooting
Reconnect store appears
Symptom: Public Lookup cannot be enabled.
Likely cause: The commerce integration is missing the app-proxy permission.
Fix: Select Reconnect store, approve the requested access, and return to Public Lookup.
Confirm: The platform warning clears and the setting saves.
A genuine serial returns unknown
Symptom: A known unit does not validate.
Likely cause: The serial was entered differently, the unit is voided, or lookup is disabled for the store.
Fix: Copy the display serial from the unit passport and verify its lifecycle status.
Confirm: The synthetic genuine result shows only the allowed public product fields.
Public Lookup pauses automatically
Symptom: The settings show a tripped availability circuit.
Likely cause: Daily public traffic crossed the configured protection threshold.
Fix: Review lookup traffic and serial entropy before resetting or increasing exposure. Do not disable abuse protection to hide the symptom.
Confirm: Normal traffic resumes without repeated threshold trips.
Privacy and responsibility
Public results are designed to minimize disclosure, but merchants remain responsible for publishing hard-to-guess serials, choosing an appropriate support route, and responding to suspected counterfeit activity.
Related articles
Was this article helpful?
Let us know — your feedback helps us improve our documentation.