ST-2026-038 · Authentication & identity
Shopify card-deposit endpoint requires a Shopify-issued mTLS certificate
Shopify requires apps using named customer payment-method credit-card mutations to authenticate to the card-deposit endpoint with a Shopify-issued mutual-TLS certificate by 15 October 2026.
Previous state
Eligible apps could submit card deposits without the new Shopify-issued mTLS certificate requirement.
Current state
Requests for the named card-create and card-update workflows must present a current Shopify-issued client certificate.
Affected users
Who needs to care
Payment app developers and operators using customerPaymentMethodCreditCardCreate or customerPaymentMethodCreditCardUpdate.
Required response
What to do
Provision the certificate, implement annual rotation, test mTLS handshakes and monitor expiry before the enforcement date.
Evidence boundary
What the source does not prove
Remote creation is outside this change. A missed certificate rotation prevents card deposits but the notice does not establish failure of unrelated Admin API calls.
Lifecycle history
Dated event sequence
- Change documented
Shopify requires apps using named customer payment-method credit-card mutations to authenticate to the card-deposit endpoint with a Shopify-issued mutual-TLS certificate by 15 October 2026.
- Effective milestone
Requests for the named card-create and card-update workflows must present a current Shopify-issued client certificate.
Evidence ledger
First-party sources
- 01Shopify Dev — Card deposit endpoint now requires mTLS certificate
Official product documentation or changelog · 2026-07-16
Open official source ↗