Multi-store isolation
Tenancy Shepherd
Run many of your own stores on one host — each with its own catalog, orders, and keys.
Need ten brands, ten dealer sites, or ten client stores on infrastructure you already run? Tenancy Shepherd isolates every storefront on a single Strapi host. $5/month on self-hosted Core when you operate multiple stores yourself.
- Isolate 2–N storefronts you operate on one self-hosted host
- Per-store catalog, carts, orders, and satellite plugin data
- Store switcher for multi-brand / multi-client operators
- Tenant credential vault with platform key fallbacks
- $5/mo optional license on self-hosted Core
- Safe to omit on single-merchant Plus installs
Self-host one stack. Run many stores.
Agencies and multi-brand operators often need ten isolated shops without ten databases. Tenancy Shepherd scopes every registered content type to the active storefront so Store A never sees Store B’s products, orders, or Stripe keys — on the same host you already pay for.
- Storefront ownership on every listable merchant content type
- One document middleware enforces reads, creates, updates, and deletes
- Store switcher when you manage more than one storefront
- Merchant-only admin chrome — platform Settings stay out of store-scoped view
Built for operators with multiple stores — not a Lite add-on.
Shepherd Lite uses the same isolation technology on the shared host so each Lite merchant gets one private storefront. Lite merchants do not unlock multi-store or a store switcher for themselves. This plugin is the paid product for self-hosted Core when you want that multi-store setup on your own infrastructure.
- Self-hosted Core — install + license plugin-tenancy at $5/mo for multi-store
- Plus / single-merchant — omit the package; no tenancy overhead
- Lite shared host — platform uses tenancy so merchants stay isolated from each other
- SHEPHERD_TENANCY_ENABLED=false disables scoping without uninstalling
Credentials that belong to each store.
Each storefront can bring its own Stripe, Shippo, or other keys without editing host env vars. Secrets are vaulted per storefront; store-scoped admins see that a platform key is configured, never the raw value.
- Tenant vault wins, then platform env, then plugin fallback
- Secret paths never written into the shared host settings row
- Admin responses redact platform key material
- Uses the shared settings store every Shepherd plugin already uses
What's inside.
$5/mo self-hosted
Optional Core add-on when you license multi-store isolation.
Your stores, your host
Agencies and multi-brand operators — not a per-merchant Lite upgrade.
Store switcher
Operators with many storefronts flip context in admin.
Fail closed
Missing storefront context denies scoped mutations — nav hiding is UX only.
Related platform features
Ten stores. One host. Real isolation.
License multi-store isolation on self-hosted Core for $5/month when you operate many storefronts yourself.