Briefing

Shopify Tightens Rate Limits for Bots Using Storefront API

e-commerce
Shopify Cloudflare

Sign all bot requests with Web Bot Auth to avoid the strictest rate limits and consult the implementation guide for details.

What to do now

Sign all bot requests with Web Bot Auth and review the implementation guide; if higher limits are needed, submit the Shopify contact form.

Summary

Shopify has introduced stricter rate limits for bots and agents that access the Storefront API and Shopify‑hosted online store pages. Bots that do not sign their requests with Web Bot Auth are subject to the most restrictive limits, while authenticated requests receive higher thresholds.

To qualify for these elevated limits, developers must sign all bot requests using the Web Bot Auth protocol. Merchants can also use pre‑generated Web Bot Auth signatures available directly in the Shopify admin for crawling their own stores. If a bot or agent requires limits beyond what Web Bot Auth offers, Shopify provides a contact form for higher‑tier access.

The change does not require enrollment with Cloudflare; the implementation guide from Cloudflare is provided for reference only. The updated rate‑limit policy is documented in Shopify’s Storefront API usage guide and is effective immediately for all bots and agents interacting with storefronts.

Key changes

  • Shopify now enforces stricter rate limits on bots/agents accessing the Storefront API and storefront pages
  • Unauthenticated bot requests hit the strictest limits
  • Signing requests with Web Bot Auth grants higher rate limits
  • Merchants can use built‑in Web Bot Auth signatures in the admin
  • For limits beyond Web Bot Auth, contact Shopify via the provided form
  • No need to enroll with Cloudflare; just implement Web Bot Auth
  • Rate‑limit details are documented in Shopify’s Storefront API usage guide

Affects

e-com-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting