Built for ShopifyAction Required

Returns/exchanges apps and subscription apps must now use
"Customer Account API authentication"

Effective December 1, 2026. Returns/exchanges apps and subscription apps that offer buyer-facing self-service features must use the Customer Account API for customer authentication. Failing to comply by the deadline risks losing Built for Shopify status.

On this page
  1. Understand it in 30 seconds: What's changing
  2. Which apps are affected
  3. Diagram: The unified sign-in concept
  4. What you need to do
  5. Deadline and risk of non-compliance
  6. 5 key points for developers
  7. 3 use cases you can apply to your work
  8. A one-line summary for your pitch

1Understand it in 30 seconds: What's changing

December 1, 2026onward, returns/exchanges apps and subscription apps that offer buyer-facing self-service features Returns/exchanges appsandSubscription appsmust use Customer Account API for customer authentication.
This lets buyers and merchants share "a single secure sign-in" across the storefront, apps, and customer accounts.

Before: Authentication left to each app

With app-specific logins or individual authentication methods, buyers were sometimes asked to sign in separately for each app.

After: Unified on the Customer Account API

Buyers can use a single secure sign-in across the storefront, apps, and customer accounts.

2Which apps are affected

The followingfalls into one of these categoriesandoffers self-service features to buyersSuch apps are affected.

Affected category A

Returns/exchanges apps

Example: Apps that offer buyer-facing self-service features such as managing returns and tracking exchanges.

Affected category B

Subscription apps

Example: Apps that offer self-service features letting buyers renew or change their subscriptions.

The criterion is whether it is "buyer-facing self-service". The concrete examples listed in the article are "managing returns," "tracking exchanges," and "renewing subscriptions." Apps like these, which have screens that buyers operate themselves, qualify.

3Diagram: The concept of unified sign-in

Buyer Sign in once Customer Account API Storefront App (Returns / Subscriptions) Customer account Single Secure Sign-in
By making the Customer Account API the gateway for customer authentication, buyers cansign in once across the storefront, apps, and customer account. On the merchant side, authentication is also unified.

4What you need to do

1

Determine eligibility

Check whether your app is a "returns / exchanges" or "subscriptions" app and qualifies as buyer-facing self-service.

2

Integrate the Customer Account API

Implement customer authentication for buyer-facing flows using the Customer Account API.

3

Review the updated requirements

Check the details in the updated Built for Shopify requirements and make sure nothing is missed.

5Deadline and risk of non-compliance

ItemDetails
Effective date / deadline December 1, 2026 The requirement takes effect on this date
Requirement Use the Customer Account API for customer authentication in buyer-facing self-service
If not addressed Risk Apps that fail to meet the requirement by the deadline risk losing their Built for Shopify status
The specific "process for determining status revocation" and any "grace period or exceptions" arenot describedin the article. Check the details in the updated Built for Shopify requirements.

65 points engineers should keep in mind

1. Consolidate authentication on the Customer Account API

In the buyer-facing flows of affected apps, the customer authentication method must be replaced with the Customer Account API. A setup relying solely on custom login will fail to meet the requirement.

2. Two categories × self-service

Applies to apps that fall under either "returns and exchanges" or "subscriptions" and that offer buyer-facing self-service. The two conditions are evaluated together as an AND.

3. Unified sign-in is the goal

The aim is a "single, secure sign-in" that spans the storefront, the app, and customer accounts. A consistent authentication UX is the rationale behind the requirement.

4. Falling short risks losing BFS status

If the requirement isn't met by the deadline, there's a risk of losing Built for Shopify status. Plan around the impact on the visibility and trust that depend on the BFS badge.

2026 12 / 1

5. The deadline is December 1, 2026 — schedule by working backward

Since the enforcement date is fixed, work backward to leave room for implementation, testing, and review. Note that the specific implementation steps, scopes, and migration guide details for the Customer Account API arenot coveredin this article, so confirm them separately in the updated Built for Shopify requirements and the official documentation.

7Three use cases you can put to work

Returns / Subscriptions
USE CASE 1

Audit the authentication in your existing apps to lock in "keeping BFS"

Challenge
You offer a returns-and-exchanges or subscription app, but its buyer-facing self-service still uses a custom authentication method, and it's unclear whether you meet the requirement.
Approach
Determine eligibility → integrate the authentication flow with the Customer Account API → cross-check against the updated Built for Shopify requirements and close any gaps.
Impact
You can keep your Built for Shopify status on and after December 1, 2026, and avoid the risk of losing it.
Technical notes
Eligibility is the AND condition of "falling under the two categories × buyer-facing self-service." Distinguish it from admin-facing screens, which don't apply, when making the call.
Store App
USE CASE 2

Eliminate buyers' "re-login per app" to reduce drop-off

Challenge
Buyers are asked to sign in separately on the storefront and in the app, causing drop-off partway through a return request or a subscription change.
Approach
Adopt the Customer Account API to unify the storefront, the app, and customer accounts under a single, secure sign-in.
Impact
Login friction in self-service actions is reduced, and you can expect higher completion rates for returns, exchanges, and subscription management.
Technical notes
The value the article highlights is a "single sign-in that spans everything." You can achieve both the UX improvement and BFS requirement compliance in the same implementation.
Migration roadmap 12/1
USE CASE 3

Build a "compliance project plan" by working backward from the enforcement date

Challenge
You have several affected apps, and the sequence of implementation, testing, and review isn't clear against the December 1, 2026 deadline.
Approach
Inventory the affected apps → implement the Customer Account API integration → cross-check against the updated requirements → schedule testing and review before the deadline by working backward.
Impact
You avoid last-minute scrambles and the risk of losing BFS from unmet requirements, and can maintain your status in a planned way.
Technical notes
The specific implementation steps and migration guide aren't covered in this article. Refer to the updated Built for Shopify requirements and the official documentation as your primary sources.

8A one-line summary you can use in a pitch

"Apps with buyer-facing self-service —returns/exchange apps and subscription apps
December 1, 2026must integrate customer authentication by Customer Account API —or, if they don't integrate it, they
risk losing their Built for Shopify status. And with unified sign-in, you can improve the UX at the same time."