October 11, 2026
Cart
- At sign-in the guest cart merges into the account’s cart, at checkout too: no more lost items when the store asks shoppers to sign in to pay. Details.
October 10, 2026
A major release of the admin area and the storefront. The changes are designed not to break existing clients, but some need action on your side. This entry also covers the October 9 changes not yet described here: “sign out everywhere”, 2FA enabled with the current password, validation errors in the standard envelope (validation.failed).
Security and authentication
- Rotating refresh tokens with reuse detection: every refresh returns a new refresh
token. A 60-second grace period covers tabs and concurrent requests; for a staff account,
reusing a superseded token closes the session (401
auth.refresh_token_reused). Tokens issued before the release are valid once and then move to the new scheme. Details. POST /auth/logoutcloses the session of the refresh token presented;?all=truecloses every session of the account (401auth.session_revokedon earlier tokens).- Single-use TOTP codes and 10 recovery codes on first 2FA activation, which can be
regenerated with
POST /auth/2fa/recovery-codes.GET /auth/meexposesrecovery_codes_remainingandis_owner. - Deleted store: 403
auth.tenant_unavailableat login and refresh.
Cart, checkout, and gift vouchers
- The cart exposes
items[].unit_price(the applied price),min_order_total, andguest_checkout_enabled;variant.sale_priceisnulloutside the sale window. - The checkout enforces the store rules: 422
checkout.min_order_not_met, 401checkout.login_required, 422checkout.payment_method_disabled. - Gift voucher at checkout with
voucher_code: balance reserved and released if the payment doesn’t go through, order paid directly (payment_method: "voucher") when the voucher covers everything,voucher.*errors. - A coupon’s discount never exceeds the subtotal; a “free shipping” coupon zeroes the shipping cost.
- “Pay now” (
POST /orders/{order_id}/pay, which reopens the payment of an online order) is now documented; capturing PayPal on a canceled order answers 400order.not_payable. Details.
Pricing and catalog
- Cart and checkout apply special prices and the customer-group rule: what the cart shows is what the checkout charges.
- The product detail has
special_priceandstock_status_name; thein_stockand price filters and the price ordering work on the effective price. - Special prices and quantity discounts only with a price greater than zero (422
product.price_rule_not_positive).
Orders, subscriptions, and storefront
- The order history the customer sees contains only status changes and public notes.
- Subscriptions: new terminal status
completed; at purchase the customer pays the product price and the trial only moves the first renewal. POST /marketing/trackcounts visits from campaign links;GET /settings/store-infoexposescatalogandseo.
Admin API
- Refunds and “mark as paid” only for some roles (403
order.refund_forbidden,order.payment_forbidden); affiliate payment details also require thereportspermission. - Stable, protected store owner (
is_owner, 403user.owner_protectedanduser.owner_only, 409user.last_admin). - API tokens don’t manage users or credentials (403
auth.api_token_forbidden). PATCH /admin/orders/{id}torefundedperforms a real refund; returns start from the order lines.POST /admin/productssaves every field and creates inline variants (409product.sku_taken).- Validated coupons and real deletion of never-used ones; gift vouchers with balance and history.
- Recurring plans:
duration= interval,cycle= total charges. - Customer anonymization, affiliate commissions per currency, reports with net revenue in the
store’s currency and time zone,
orders.guest_checkout_allowedsetting. Details.
Webhooks
- HTTPS-only URLs to public hosts (422
webhooks.url_https_required,webhooks.url_not_public,webhooks.url_invalid). - Test delivery, redelivery, secret rotation, and a safe excerpt of the response in the delivery log. Details.
- New
order.refundedevent for total and partial refunds; every order event carriesamount_refunded.
MCP
- The admin
update_order_statustool withstatus: "refunded"performs a real refund of the remaining amount through the payment gateway. The other tools are unchanged. Details.