Effective December 1, 2026. Returns/exchanges apps and subscription apps that offer buyer-facing self-service features must use the Customer Account API for customer authentication. Failing to comply by the deadline risks losing Built for Shopify status.
With app-specific logins or individual authentication methods, buyers were sometimes asked to sign in separately for each app.
Buyers can use a single secure sign-in across the storefront, apps, and customer accounts.
The followingfalls into one of these categoriesandoffers self-service features to buyersSuch apps are affected.
Example: Apps that offer buyer-facing self-service features such as managing returns and tracking exchanges.
Example: Apps that offer self-service features letting buyers renew or change their subscriptions.
Check whether your app is a "returns / exchanges" or "subscriptions" app and qualifies as buyer-facing self-service.
Implement customer authentication for buyer-facing flows using the Customer Account API.
Check the details in the updated Built for Shopify requirements and make sure nothing is missed.
| Item | Details |
|---|---|
| Effective date / deadline | December 1, 2026 The requirement takes effect on this date |
| Requirement | Use the Customer Account API for customer authentication in buyer-facing self-service |
| If not addressed | Risk Apps that fail to meet the requirement by the deadline risk losing their Built for Shopify status |
In the buyer-facing flows of affected apps, the customer authentication method must be replaced with the Customer Account API. A setup relying solely on custom login will fail to meet the requirement.
Applies to apps that fall under either "returns and exchanges" or "subscriptions" and that offer buyer-facing self-service. The two conditions are evaluated together as an AND.
The aim is a "single, secure sign-in" that spans the storefront, the app, and customer accounts. A consistent authentication UX is the rationale behind the requirement.
If the requirement isn't met by the deadline, there's a risk of losing Built for Shopify status. Plan around the impact on the visibility and trust that depend on the BFS badge.
Since the enforcement date is fixed, work backward to leave room for implementation, testing, and review. Note that the specific implementation steps, scopes, and migration guide details for the Customer Account API arenot coveredin this article, so confirm them separately in the updated Built for Shopify requirements and the official documentation.