Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- Affected apps deposit card details at https://checkout-mtls.pci.shopifyinc.com/sessions, obtain a session identifier, then call customerPaymentMethodCreditCardCreate or customerPaymentMethodCreditCardUpdate.
- Apps using only customerPaymentMethodRemoteCreate to import references to payment methods already stored at external gateways are outside this mTLS deposit change.
- The deposit endpoint, GraphQL vault mutations and OAuth flow remain unchanged. The new requirement is a Shopify-issued client certificate on /sessions requests.
- Shopify manually issues the first certificate. Official instructions request the API client ID and technical contact by email and warn this may take several days; allow validation time before October 15.
- After the first certificate, rotation can be self-served through Shopify Certificate Signing Service. Certificates last one year; expiry or missed rotation stops new card deposits.
Define scope first: only apps directly depositing card details need migration
Shopify announced on July 16, 2026 that mTLS client certificates for the card-deposit endpoint would become mandatory on October 15, 2026. The affected flow submits card details to /sessions, obtains a session identifier, then passes it to customerPaymentMethodCreditCardCreate or customerPaymentMethodCreditCardUpdate.
Search code, configuration, call logs and architecture inventories for those two mutations, checkout-mtls.pci.shopifyinc.com/sessions and sessionId. If the app only calls customerPaymentMethodRemoteCreate to import references to payment methods already stored at external gateways such as Stripe, Braintree, Authorize.Net, Adyen or PayPal, official guidance explicitly says no action is needed for this change.
What changes and what stays the same
The endpoint remains https://checkout-mtls.pci.shopifyinc.com/sessions. The two GraphQL Admin API vault mutations still accept the session identifier returned by deposit, and the OAuth flow is unaffected. Do not change endpoint, mutation and authentication together, turning a single-certificate migration into a high-risk redesign.
Only the deposit connection changes: every request must present a valid Shopify-issued mTLS client certificate. Once enforcement begins, requests without a certificate or with an invalid certificate cannot deposit new card details. The announcement does not establish an impact on existing payment methods, external-gateway references or other paths that do not use this endpoint.
Apply for the first Shopify certificate
Official instructions say to request the first certificate from [email protected], providing the API client ID and technical contact. Shopify issues it manually and this may take several days. Schedule application, receipt, deployment, validation and contingency time before October 15.
Editorial implementation guidance: send only the identifiers and contact information officially requested. Do not send private keys, access tokens, complete card details or production certificate contents through ordinary email, tickets, repositories or logs. Generate and store private keys in a controlled PCI-compliant environment. Define certificate/private-key read permissions, auditing and rotation ownership before deployment.
Keep certificate integration small and verifiable before deployment
The following integration, static-check and canary steps are editorial implementation guidance and must respect application authorization and payment-data boundaries. Load the client certificate and matching private key in the HTTP client’s or outbound proxy’s /sessions-specific configuration, retaining the current endpoint, request fields and subsequent GraphQL calls. Separate test and production certificates, key paths, secret names and expiry alerts. Log only certificate fingerprints or internal version numbers, never private keys or card details.
Perform static checks first: the certificate chain loads, certificate and private key match, the runtime identity can read the secret, and target hostname and TLS verification remain enabled. Do not disable server-certificate verification, weaken TLS settings or bake certificates into images to obtain one successful connection.
Canary validation: establish success of both deposit and the vault mutation
Choose a non-critical test customer or an officially permitted safe testing path. Send one /sessions request with the new certificate and confirm a new session identifier, then cover whichever create or update mutations the app actually uses, checking processing, customerPaymentMethod and userErrors. Successful TLS with a failed mutation is not a completed migration.
Retain sanitized request time, application version, certificate fingerprint, HTTP status, TLS error category, mutation name and userErrors. Shopify also requires confirmation that deposit traffic carries a valid certificate and its own verification of cutover. Expand only after checking limited traffic for one app; do not use real card numbers for ad hoc probes.
Failure, stop and fallback boundaries
Stop increasing traffic if the certificate is not issued, the private key mismatches, TLS handshake fails, the session identifier is missing, GraphQL userErrors are unexplained or Shopify has not confirmed cutover. Diagnose network connectivity, mTLS client authentication, OAuth, API scopes and business fields separately instead of assigning every 4xx or TLS error the same cause.
Before enforcement, traffic can return to a validated old version to restore business while certificate integration is repaired. After the October 15 requirement takes effect, however, a certificate-free deposit path is not a lasting rollback option. If migration cannot finish before the deadline, pause new card-deposit paths and coordinate with Shopify rather than disabling TLS verification or retrying real payment data.
One-year validity is not a one-time task: rotation and network boundaries
Shopify says that after the first certificate, Certificate Signing Service supports self-service rotation, with a one-year certificate TTL. Set graduated expiry alerts, issue the next certificate early, validate dual-certificate or sequential cutover, and remove the old certificate only after the new one is stable. Missed rotation stops new deposits.
Handle certificate expiry, client-certificate-required, unknown ca and handshake failure through mTLS evidence first. Consult the proxy connection troubleshooting checklist for egress only with DNS, 407, connection timeouts or simultaneous inaccessibility of multiple official Shopify endpoints. A fixed IP cannot replace Shopify-issued certificates, PCI boundaries or certificate rotation.
Sources
Frequently Asked Questions
When does Shopify enforce the mTLS requirement?
Official guidance requires migration by October 15, 2026. After enforcement, card-deposit requests must present a valid Shopify-issued client certificate.
Do apps using only customerPaymentMethodRemoteCreate need a certificate?
Not because of this announcement. That mutation imports references to payment methods already stored at external gateways rather than depositing raw card details with Shopify, and is explicitly outside scope.
Must the endpoint, GraphQL mutation or OAuth URL change too?
No. The /sessions endpoint, customerPaymentMethodCreditCardCreate/Update and OAuth flow remain unchanged. The addition is an mTLS client certificate on deposit requests.
How do I request the first certificate?
Follow the Shopify announcement and email [email protected] with the API client ID and technical contact. Do not send private keys, tokens or card details through ordinary email.
How is successful migration established?
Confirm that the certificate-bearing /sessions request returns a session identifier, that subsequent create/update processing, results and userErrors are as expected, and that Shopify-side cutover verification is complete.
Can a fixed IP replace an mTLS certificate?
No. Fixed egress cannot prove client identity or bypass issuance, validity or PCI boundaries. Network troubleshooting requires clear DNS, 407 or connection-timeout evidence.