API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-038 · Authentication & identity

Shopify card-deposit endpoint requires a Shopify-issued mTLS certificate

Shopify requires apps using named customer payment-method credit-card mutations to authenticate to the card-deposit endpoint with a Shopify-issued mutual-TLS certificate by 15 October 2026.

ShopifymTLSpaymentsclient certificateauthentication

Previous state

Eligible apps could submit card deposits without the new Shopify-issued mTLS certificate requirement.

Current state

Requests for the named card-create and card-update workflows must present a current Shopify-issued client certificate.

Who needs to care

Payment app developers and operators using customerPaymentMethodCreditCardCreate or customerPaymentMethodCreditCardUpdate.

What to do

Provision the certificate, implement annual rotation, test mTLS handshakes and monitor expiry before the enforcement date.

What the source does not prove

Remote creation is outside this change. A missed certificate rotation prevents card deposits but the notice does not establish failure of unrelated Admin API calls.

Lifecycle history

Dated event sequence

  1. Change documented

    Shopify requires apps using named customer payment-method credit-card mutations to authenticate to the card-deposit endpoint with a Shopify-issued mutual-TLS certificate by 15 October 2026.

  2. Effective milestone

    Requests for the named card-create and card-update workflows must present a current Shopify-issued client certificate.

Evidence ledger

First-party sources

  1. 01
    Shopify Dev — Card deposit endpoint now requires mTLS certificate

    Official product documentation or changelog · 2026-07-16

    Open official source ↗