Shopify and Google sunsets
A sunset rarely breaks with an error. It keeps answering, on a version nobody chose, until a number is quietly wrong.
Audience Business analyst, platform engineer, compliance reviewer Status Current · Version 1.0 Owner Platform engineer (role) Evidence basis Platform pages read 16 September 2026; CRM Sync worker at commit 8eb2102 Review cycle Each Shopify quarterly API release; next 1 January 2027 Related Commerce API migration calendar
At a glance
Open the interactive brief: Shopify and Google Sunsets · Download the full migration calendar (.md)
Two of the five topics carry a date inside the eight weeks from 16 September to 11 November 2026: Shopify API version retirement and the Google Ads API. Neither reaches the running CRM Sync worker. One item needs work: two Shopify Flow extensions are pinned to an API version Shopify has already retired. Short-lived tokens are due on 1 January 2027, the REST shutdown has no date, the native mobile move is Shopify's own apps rather than a developer deadline, and two Google consent changes are announced for later in 2026 without a date.
Status words used below: Clear means no exposure in the running code; Action means something to change, with an owner; Watch means real but undated; Passed means already in effect.
The question this answers
Which platform changes land in the next eight weeks, and does any of them touch what is running today? It covers the five topics raised by the business — native mobile, short-lived tokens, the REST sunset, GraphQL data layers, and GA4 consent and conversions — plus every other Shopify and Google change found dated inside the window.
Terms, fixed here
| Term | Means | Is not |
|---|---|---|
| Deprecated | Announced as going away. It still works. | Removed. |
| Sunset / retired | The date the platform stops honouring it. | Always an error. Shopify serves a retired API version from the oldest supported one. |
| Fall forward | Shopify answers a retired version on a newer one; the X-Shopify-API-Version response header names it. | Safe. Removed fields return differently, still with a 200. |
| Expiring offline token | A Shopify Admin credential lasting 60 minutes, renewed by a 90-day refresh token. | A certificate. |
| Consent signal | A Consent Mode v2 value a page sends Google: ad_storage, ad_user_data, ad_personalization, analytics_storage. | A console setting. Google is moving control to these signals. |
| Data Manager API | Google's single upload endpoint for audiences and conversions. | The Google Ads API, which Customer Match and offline conversions have left. |
In words: deprecated means it still works; retired means the platform stops honouring it, and on Shopify that usually means a request quietly answered on a newer version rather than an error. An expiring offline token lasts an hour and renews from a 90-day refresh token. Consent signals, not console toggles, are becoming Google's control for advertising data.
Where these changes land: one word, three runtimes
A sunset is only urgent where the retiring thing runs, and "function" means three different things in this estate. A Xano custom function is called by your own API endpoints, tasks, triggers and other function stacks, takes named inputs, runs its function stack beside the database, and returns a response. A Shopify Function is called only by Shopify as the cart and checkout run, reads JSON shaped by its GraphQL input query, runs as a WebAssembly module inside Shopify's infrastructure, and returns operations for Shopify to carry out. A Cloudflare Worker is called by an HTTP request, a Cron Trigger or a queue message, runs in a V8 isolate in 330+ cities, and is billed for CPU time.
In words: the difference that decides where a rule belongs is who can call it. Only your own Xano stacks can call a Xano function, so it holds the record. Only Shopify can call a Shopify Function, so it holds rules that must apply inside checkout. Anyone who can reach a Worker's URL can call it, which is why the Worker holds the permissions boundary. The Shopify API version and token changes below reach code that calls Shopify from a Worker or from Xano; checkout extension changes reach code that runs inside Shopify.
Everything dated inside the window
| Date | Change | Exposure | Status |
|---|---|---|---|
| 1 Oct 2026 | Script tags: apps can no longer create or update them, in GraphQL or REST. They stop running on storefronts on 1 March 2027. | None for CRM Sync, which uses no script tags. The store is a separate question — see step 3 in what to do next. | Clear for this app |
| 1 Oct 2026 | Checkout and customer-account extensions must finish moving to Polaris web components. | None; no checkout or customer-account extensions. | Clear |
| 1 Oct 2026 | Shopify API version 2026-10 released. | No change required. | Clear |
| 7 Oct 2026 | Google Ads API v22 shut off; v22 requests fail. | None; audiences use the Data Manager API. | Clear |
| 16 Oct 2026 | Shopify API version 2025-10 retired at 15:00 UTC. | Worker on 2026-04, supported to 16 April 2027. Two Flow extensions pin 2025-01. | Action |
In words: on 1 October Shopify refuses new or updated script tags and requires Polaris web components in checkout and customer-account extensions, and CRM Sync uses neither. On 7 October Google shuts off Google Ads API v22, which CRM Sync does not call. On 16 October Shopify retires API version 2025-10; the worker runs on 2026-04, but the two Flow extensions are pinned to 2025-01 and should be moved to a supported version.
1. React Native to Swift and Kotlin
On 10 September 2026 Shopify said it is rebuilding Shopify, Shop, Point of Sale and Inbox natively — Swift on iOS, Kotlin on Android — six years after going all-in on React Native in 2020. The Shop app was first, taken from proof of concept to App Store publication in 12 weeks, "assisted by AI." CRM Sync has no React Native code.
Shopify's post publishes no benchmarks. Startup and binary-size figures circulating in secondary coverage are not in the announcement; treat them as unverified unless you find a primary source. The absence is itself worth noting on a page about platform change — the argument made was about cost of development, not runtime performance.
The stated reason is the part worth reading. In Shopify's words, "LLMs changed one of the core assumptions behind our 2020 decision," and by late 2025 "agents were capable of making us question whether building software twice still meant doing twice the work." Coding models improved to the point that "building the same feature in Swift and Kotlin no longer carries the cost it used to."
AI did not make the abstraction better. It made the reason for the abstraction smaller. That is a different species of platform change from everything else on this page, and it is likely to recur: any abstraction whose value was not writing the same thing twice now competes with something that writes it twice for very little. Worth holding against every framework choice in the estate, not just this one.
Status: Watch for Shopify's mobile SDKs following its apps. Three open-source dependencies are no longer a watch — they are dated maintenance decisions:
| Package | Shopify's commitment | After |
|---|---|---|
@shopify/react-native-skia | Sponsored through end of 2026 | Forked and republished under a new name by its maintainer; the original archived |
@shopify/restyle | Supported through end of 2026 | Archived, maintenance stops |
@shopify/flash-list | Critical fixes only | Shopify is seeking long-term stewardship partners |
Action: grep the estate for all three package names. Anything present in a shipped surface has an end-of-maintenance date inside the next year, and restyle has no successor named.
2. Short-lived tokens
From 1 January 2027 every public app must call the Admin API with expiring offline tokens; a non-expiring token gets authentication errors after that date. New public apps have needed them since 1 April 2026. Custom apps and merchant-created apps are exempt.
CRM Sync's token exchanges already request expiring tokens. What is not yet checked is whether every installed shop has switched: migration happens once per shop, cannot be undone, and a new token retires the old refresh token immediately. Status: Action — confirm per shop during October, so a missed shop is found before New Year's Day rather than on it.
3. The REST sunset
The REST Admin API has been legacy since 1 October 2024, and new public apps have been GraphQL-only since 1 April 2025. Shopify has not set a shutdown date for existing apps; the only REST change inside the window is the script tag write refusal on 1 October. CRM Sync makes one REST call, for shop details, and everything else is GraphQL. Status: Watch, with an optional action to move that call to the GraphQL shop query so nothing depends on REST when a date is set.
4. GraphQL data layers
| Change | Date | Exposure | Status |
|---|---|---|---|
| API version 2025-10 retired | 16 Oct 2026 | Flow extensions on 2025-01 already fall forward | Action |
| API version 2026-04 retired | 16 Apr 2027 | The worker's pinned version | Watch |
| Web pixel events strip name, email, phone and address unless the app is approved for protected customer data | 10 Dec 2025 | Anything reading email from pixel events receives blanks | Passed |
| Additional scripts stop on non-Plus Thank you and Order status pages | 26 Aug 2026 | Tracking comes from Customer Events | Passed |
In words: the version clock is the live risk — 2025-10 retires on 16 October and 2026-04, the worker's version, on 16 April 2027. Two data-layer changes are already in effect: since 10 December 2025 web pixel events carry no customer name, email, phone or address unless the app holds approved protected customer data access, and since 26 August 2026 additional scripts no longer run on non-Plus Thank you and Order status pages.
5. GA4, consent v2 and conversion sunsets
| Change | Date | Exposure | Status |
|---|---|---|---|
| Customer Match uploads moved from the Google Ads API to the Data Manager API | 1 Apr 2026 | Already on the Data Manager API | Passed |
| Offline conversion uploads left the Google Ads API | 15 Jun 2026 | Not used | Passed |
ad_storage alone decides whether GA4 data reaches Google Ads; the Google Signals setting no longer does | 15 Jun 2026 | Consent signals are sent before any tag loads | Passed |
Ads personalization settings move from GA4 to Google Ads; ad_personalization becomes the only control | Later 2026, undated | Signals already sent; confirm the Ads account setting matches when dated | Watch |
| IP addresses the Google tag collects are encrypted and sent to the linked Ads account | Later 2026, undated | No code change; re-read any privacy notice that describes IP handling | Watch |
GA4 user deletion runs on Google's v1alpha admin API | No date | Alpha versions can change without the usual notice | Watch |
In words: three Google changes have already happened. Customer Match uploads moved to the Data Manager API on 1 April 2026, which CRM Sync already uses; offline conversion uploads left the Google Ads API on 15 June 2026, which CRM Sync does not use; and since 15 June the ad_storage consent signal alone decides whether GA4 data reaches Google Ads. Later in 2026, on a date Google has not announced, ads personalization settings move from GA4 into Google Ads with ad_personalization as the only control, and tag-collected IP addresses are encrypted and sent to the linked Ads account. CRM Sync already sends ad_personalization and ad_user_data; when Google sets the date, the Google Ads account's setting should be checked against the signal. The GA4 user deletion used for privacy requests runs on an alpha API, so a deletion that starts failing should be diagnosed with the GA4 deletion preflight first.
Just past the window
| Date | Change | Exposure | Status |
|---|---|---|---|
| 1 Dec 2026 | Returns and subscription apps need Customer Account API sign-in to keep Built for Shopify status | Does not apply | Clear |
| 1 Jan 2027 | Expiring offline tokens required for all public apps | Exchange ready; per-shop migration unchecked | Action |
| 1 Jan 2027 | POS Liquid receipt templates converted automatically | No POS receipts | Clear |
| 1 Mar 2027 | Script tags stop running on storefronts | None used | Clear |
In words: on 1 December 2026 returns and subscription apps need Customer Account API sign-in for Built for Shopify status, which does not apply to CRM Sync. On 1 January 2027 expiring offline tokens become mandatory for all public apps, and POS Liquid receipt templates are converted automatically. On 1 March 2027 script tags stop running on storefronts.
What it costs to leave these alone
| Left alone | What it looks like from outside | Severity |
|---|---|---|
| Flow extensions on 2025-01 | Flow runs keep succeeding on a substituted version; a field that changed shape returns empty, and nothing errors | Medium, silent |
| A shop not migrated to expiring tokens | Admin calls for that one shop fail from 1 January while every other shop works | High, dated |
| Ads personalization dated without notice | Personalized audiences shift because the Ads setting disagrees with the consent signal | Medium, undated |
| GA4 alpha API changes | A privacy deletion records that Google was not instructed | Low; the record says so |
In words: the most expensive item is a shop left on a non-expiring token, because it fails on a known date and only for that shop. The quietest is the Flow extension version, which never errors — it returns different data with a success status.
What this does not claim. It covers the five topics raised and the Shopify and Google changes found dated inside the window. It is not a full audit of every Shopify changelog entry, and the React Native finding reflects what Shopify has published about its own apps, not a guarantee about its SDKs.
What to do next
- Bump both Flow extensions off 2025-01 to a supported API version and deploy the app. Owner: platform engineer.
- Confirm every installed shop holds an expiring token during October. Owner: platform engineer.
- Scan the storefront for script tags that are not yours. The table above says CRM Sync uses none, and that answers whether this app breaks — not whether the store does. A shop can carry script tags installed by apps years ago, including apps since uninstalled, and every one of them stops running on 1 March 2027. Two steps, because they answer different questions:
- Capture a HAR on a live product page and a cart page, and list every third-party script that actually loads. See How to capture a HAR. This tells you what is running.
- Query the shop's script tags through the Admin API and compare the two lists. This tells you how each one is delivered — the same reviews, loyalty or upsell widget may arrive via a script tag, a theme app embed, or a line someone pasted into the theme years ago. Only the first has a death date; only the last is invisible to both the app list and the vendor.
Anything appearing in both lists needs the vendor asked a direct question: have you moved to a theme app embed, and by when. A vendor that has already migrated will say so immediately. A vendor that has not is a dated outage on someone else's schedule. Owner: platform engineer with the merchant's app owner.
- Match the Google Ads personalization setting to the
ad_personalizationsignal when Google dates the change. Owner: Revenue BA with the Google Ads account owner. - Replace the last REST call with the GraphQL
shopquery. Owner: platform engineer. Optional. - Review again on 1 January 2027, when 2027-01 releases and three months before 2026-04 retires. Owner: platform engineer.
Sources
Platform pages are primary; agency and news articles are secondary and were used only for dates a platform page did not state.
Shopify
- About Shopify API versioning — https://shopify.dev/docs/api/usage/versioning
- Shopify developer changelog: action required — https://shopify.dev/changelog?filter=action-required
- Expiring offline access tokens required for all public apps as of January 1, 2027 — https://shopify.dev/changelog/expiring-offline-access-tokens-required-for-all-public-apps-as-of-january-1-2027
- Pixel Privacy — https://shopify.dev/docs/api/web-pixels-api/pixel-privacy
- Native is now the future of mobile at Shopify — https://shopify.engineering/back-to-native
- Updates to Google Analytics Data Controls — https://support.google.com/analytics/answer/17016975?hl=en
- Google Ads API deprecation and sunset dates — https://developers.google.com/google-ads/api/docs/sunset-dates
- Google Ads API v22 sunset reminder — https://ads-developers.googleblog.com/2026/09/google-ads-api-v22-sunset-reminder.html
- Google Ads API v21 sunset reminder — https://ads-developers.googleblog.com/2026/06/google-ads-api-v21-sunset-reminder.html
Secondary
- Shopify script tags are being switched off: the two dates that matter — https://learnshopify.dev/blog/shopify-script-tags-deprecated
- Shopify Updates August 2026 (Fudge) — https://www.fudge.ai/blog/shopify-updates-august-2026/
- Shopify breaking changes 2026 (Weaverse) — https://weaverse.io/blogs/shopify-developer-breaking-changes-april-2026
- Shopify drops React Native for Swift and Kotlin (InfoQ) — https://www.infoq.com/news/2026/09/shopify-drops-react-native/
- Native is now the future of mobile at Shopify — https://shopify.engineering/back-to-native
- Shopify spent years on React Native, then rebuilt in 12 weeks (The New Stack) — https://thenewstack.io/shopify-native-ai-agents/
- Shopify's REST API deprecation and GraphQL migration (Lazer) — https://www.lazertechnologies.com/insights/shopifys-rest-api-deprecation-and-graphql-migration-guide
- What customer data Shopify redacts from web pixel events (WeltPixel) — https://weltpixel.com/blogs/news/what-customer-data-is-available-in-shopify-web-pixel-events-and-what-shopify-redacts
- GA4 and Google Ads data controls: what changes June 15, 2026 (Dataslayer) — https://www.dataslayer.ai/blog/ga4-google-ads-data-controls-june-15-2026
- Google forces Customer Match uploads to Data Manager API by April 1 (PPC Land) — https://ppc.land/google-forces-customer-match-uploads-to-data-manager-api-by-april-1/
- Google is moving offline conversion imports out of the Google Ads API (Search Engine Land) — https://searchengineland.com/google-is-moving-offline-conversion-imports-out-of-the-google-ads-api-477669
Platform dates read 16 September 2026. Dates marked "later 2026" are unannounced by the platform, not estimated here. This is a change brief, not a certification.
