Skip to main content

October 11, 2026

Cart

  • At sign-in the guest cart merges into the account’s cart, at checkout too: no more lost items when the store asks shoppers to sign in to pay. Details.

October 10, 2026

A major release of the admin area and the storefront. The changes are designed not to break existing clients, but some need action on your side. This entry also covers the October 9 changes not yet described here: “sign out everywhere”, 2FA enabled with the current password, validation errors in the standard envelope (validation.failed).
To do in your clients
  • Always store the new refresh token returned by every POST /auth/refresh.
  • In the cart show unit_price, not variant.price or variant.sale_price.
  • Take the payment methods from GET /settings/payment-methods and always send payment_method: the checkout rejects methods that are switched off.
  • Treat the refunded status (Admin API and MCP) as a money movement.
  • Translate the new error_code values listed below.

Security and authentication

  • Rotating refresh tokens with reuse detection: every refresh returns a new refresh token. A 60-second grace period covers tabs and concurrent requests; for a staff account, reusing a superseded token closes the session (401 auth.refresh_token_reused). Tokens issued before the release are valid once and then move to the new scheme. Details.
  • POST /auth/logout closes the session of the refresh token presented; ?all=true closes every session of the account (401 auth.session_revoked on earlier tokens).
  • Single-use TOTP codes and 10 recovery codes on first 2FA activation, which can be regenerated with POST /auth/2fa/recovery-codes. GET /auth/me exposes recovery_codes_remaining and is_owner.
  • Deleted store: 403 auth.tenant_unavailable at login and refresh.

Cart, checkout, and gift vouchers

  • The cart exposes items[].unit_price (the applied price), min_order_total, and guest_checkout_enabled; variant.sale_price is null outside the sale window.
  • The checkout enforces the store rules: 422 checkout.min_order_not_met, 401 checkout.login_required, 422 checkout.payment_method_disabled.
  • Gift voucher at checkout with voucher_code: balance reserved and released if the payment doesn’t go through, order paid directly (payment_method: "voucher") when the voucher covers everything, voucher.* errors.
  • A coupon’s discount never exceeds the subtotal; a “free shipping” coupon zeroes the shipping cost.
  • “Pay now” (POST /orders/{order_id}/pay, which reopens the payment of an online order) is now documented; capturing PayPal on a canceled order answers 400 order.not_payable. Details.

Pricing and catalog

  • Cart and checkout apply special prices and the customer-group rule: what the cart shows is what the checkout charges.
  • The product detail has special_price and stock_status_name; the in_stock and price filters and the price ordering work on the effective price.
  • Special prices and quantity discounts only with a price greater than zero (422 product.price_rule_not_positive).

Orders, subscriptions, and storefront

  • The order history the customer sees contains only status changes and public notes.
  • Subscriptions: new terminal status completed; at purchase the customer pays the product price and the trial only moves the first renewal.
  • POST /marketing/track counts visits from campaign links; GET /settings/store-info exposes catalog and seo.

Admin API

  • Refunds and “mark as paid” only for some roles (403 order.refund_forbidden, order.payment_forbidden); affiliate payment details also require the reports permission.
  • Stable, protected store owner (is_owner, 403 user.owner_protected and user.owner_only, 409 user.last_admin).
  • API tokens don’t manage users or credentials (403 auth.api_token_forbidden).
  • PATCH /admin/orders/{id} to refunded performs a real refund; returns start from the order lines.
  • POST /admin/products saves every field and creates inline variants (409 product.sku_taken).
  • Validated coupons and real deletion of never-used ones; gift vouchers with balance and history.
  • Recurring plans: duration = interval, cycle = total charges.
  • Customer anonymization, affiliate commissions per currency, reports with net revenue in the store’s currency and time zone, orders.guest_checkout_allowed setting. Details.

Webhooks

  • HTTPS-only URLs to public hosts (422 webhooks.url_https_required, webhooks.url_not_public, webhooks.url_invalid).
  • Test delivery, redelivery, secret rotation, and a safe excerpt of the response in the delivery log. Details.
  • New order.refunded event for total and partial refunds; every order event carries amount_refunded.

MCP

  • The admin update_order_status tool with status: "refunded" performs a real refund of the remaining amount through the payment gateway. The other tools are unchanged. Details.