Reference

Shopify and Google sunsets

A sunset rarely breaks with an error. It keeps answering, on a version nobody chose, until a number is quietly wrong.

Audience Business analyst, platform engineer, compliance reviewer Status Current · Version 1.0 Owner Platform engineer (role) Evidence basis Platform pages read 16 September 2026; CRM Sync worker at commit 8eb2102 Review cycle Each Shopify quarterly API release; next 1 January 2027 Related Commerce API migration calendar


At a glance

Open the interactive brief: Shopify and Google Sunsets · Download the full migration calendar (.md)

Two of the five topics carry a date inside the eight weeks from 16 September to 11 November 2026: Shopify API version retirement and the Google Ads API. Neither reaches the running CRM Sync worker. One item needs work: two Shopify Flow extensions are pinned to an API version Shopify has already retired. Short-lived tokens are due on 1 January 2027, the REST shutdown has no date, the native mobile move is Shopify's own apps rather than a developer deadline, and two Google consent changes are announced for later in 2026 without a date.

Status words used below: Clear means no exposure in the running code; Action means something to change, with an owner; Watch means real but undated; Passed means already in effect.


The question this answers

Which platform changes land in the next eight weeks, and does any of them touch what is running today? It covers the five topics raised by the business — native mobile, short-lived tokens, the REST sunset, GraphQL data layers, and GA4 consent and conversions — plus every other Shopify and Google change found dated inside the window.

Terms, fixed here

TermMeansIs not
DeprecatedAnnounced as going away. It still works.Removed.
Sunset / retiredThe date the platform stops honouring it.Always an error. Shopify serves a retired API version from the oldest supported one.
Fall forwardShopify answers a retired version on a newer one; the X-Shopify-API-Version response header names it.Safe. Removed fields return differently, still with a 200.
Expiring offline tokenA Shopify Admin credential lasting 60 minutes, renewed by a 90-day refresh token.A certificate.
Consent signalA Consent Mode v2 value a page sends Google: ad_storage, ad_user_data, ad_personalization, analytics_storage.A console setting. Google is moving control to these signals.
Data Manager APIGoogle's single upload endpoint for audiences and conversions.The Google Ads API, which Customer Match and offline conversions have left.

In words: deprecated means it still works; retired means the platform stops honouring it, and on Shopify that usually means a request quietly answered on a newer version rather than an error. An expiring offline token lasts an hour and renews from a 90-day refresh token. Consent signals, not console toggles, are becoming Google's control for advertising data.


Where these changes land: one word, three runtimes

One word, three runtimes: what a function is in Xano, Shopify and Cloudflare — who calls it, what it reads, where it runs, and who can call it

Open the illustration as SVG

A sunset is only urgent where the retiring thing runs, and "function" means three different things in this estate. A Xano custom function is called by your own API endpoints, tasks, triggers and other function stacks, takes named inputs, runs its function stack beside the database, and returns a response. A Shopify Function is called only by Shopify as the cart and checkout run, reads JSON shaped by its GraphQL input query, runs as a WebAssembly module inside Shopify's infrastructure, and returns operations for Shopify to carry out. A Cloudflare Worker is called by an HTTP request, a Cron Trigger or a queue message, runs in a V8 isolate in 330+ cities, and is billed for CPU time.

In words: the difference that decides where a rule belongs is who can call it. Only your own Xano stacks can call a Xano function, so it holds the record. Only Shopify can call a Shopify Function, so it holds rules that must apply inside checkout. Anyone who can reach a Worker's URL can call it, which is why the Worker holds the permissions boundary. The Shopify API version and token changes below reach code that calls Shopify from a Worker or from Xano; checkout extension changes reach code that runs inside Shopify.


Everything dated inside the window

DateChangeExposureStatus
1 Oct 2026Script tags: apps can no longer create or update them, in GraphQL or REST. They stop running on storefronts on 1 March 2027.None for CRM Sync, which uses no script tags. The store is a separate question — see step 3 in what to do next.Clear for this app
1 Oct 2026Checkout and customer-account extensions must finish moving to Polaris web components.None; no checkout or customer-account extensions.Clear
1 Oct 2026Shopify API version 2026-10 released.No change required.Clear
7 Oct 2026Google Ads API v22 shut off; v22 requests fail.None; audiences use the Data Manager API.Clear
16 Oct 2026Shopify API version 2025-10 retired at 15:00 UTC.Worker on 2026-04, supported to 16 April 2027. Two Flow extensions pin 2025-01.Action

In words: on 1 October Shopify refuses new or updated script tags and requires Polaris web components in checkout and customer-account extensions, and CRM Sync uses neither. On 7 October Google shuts off Google Ads API v22, which CRM Sync does not call. On 16 October Shopify retires API version 2025-10; the worker runs on 2026-04, but the two Flow extensions are pinned to 2025-01 and should be moved to a supported version.


1. React Native to Swift and Kotlin

On 10 September 2026 Shopify said it is rebuilding Shopify, Shop, Point of Sale and Inbox natively — Swift on iOS, Kotlin on Android — six years after going all-in on React Native in 2020. The Shop app was first, taken from proof of concept to App Store publication in 12 weeks, "assisted by AI." CRM Sync has no React Native code.

Shopify's post publishes no benchmarks. Startup and binary-size figures circulating in secondary coverage are not in the announcement; treat them as unverified unless you find a primary source. The absence is itself worth noting on a page about platform change — the argument made was about cost of development, not runtime performance.

The stated reason is the part worth reading. In Shopify's words, "LLMs changed one of the core assumptions behind our 2020 decision," and by late 2025 "agents were capable of making us question whether building software twice still meant doing twice the work." Coding models improved to the point that "building the same feature in Swift and Kotlin no longer carries the cost it used to."

AI did not make the abstraction better. It made the reason for the abstraction smaller. That is a different species of platform change from everything else on this page, and it is likely to recur: any abstraction whose value was not writing the same thing twice now competes with something that writes it twice for very little. Worth holding against every framework choice in the estate, not just this one.

Status: Watch for Shopify's mobile SDKs following its apps. Three open-source dependencies are no longer a watch — they are dated maintenance decisions:

PackageShopify's commitmentAfter
@shopify/react-native-skiaSponsored through end of 2026Forked and republished under a new name by its maintainer; the original archived
@shopify/restyleSupported through end of 2026Archived, maintenance stops
@shopify/flash-listCritical fixes onlyShopify is seeking long-term stewardship partners

Action: grep the estate for all three package names. Anything present in a shipped surface has an end-of-maintenance date inside the next year, and restyle has no successor named.

2. Short-lived tokens

From 1 January 2027 every public app must call the Admin API with expiring offline tokens; a non-expiring token gets authentication errors after that date. New public apps have needed them since 1 April 2026. Custom apps and merchant-created apps are exempt.

CRM Sync's token exchanges already request expiring tokens. What is not yet checked is whether every installed shop has switched: migration happens once per shop, cannot be undone, and a new token retires the old refresh token immediately. Status: Action — confirm per shop during October, so a missed shop is found before New Year's Day rather than on it.

3. The REST sunset

The REST Admin API has been legacy since 1 October 2024, and new public apps have been GraphQL-only since 1 April 2025. Shopify has not set a shutdown date for existing apps; the only REST change inside the window is the script tag write refusal on 1 October. CRM Sync makes one REST call, for shop details, and everything else is GraphQL. Status: Watch, with an optional action to move that call to the GraphQL shop query so nothing depends on REST when a date is set.

4. GraphQL data layers

ChangeDateExposureStatus
API version 2025-10 retired16 Oct 2026Flow extensions on 2025-01 already fall forwardAction
API version 2026-04 retired16 Apr 2027The worker's pinned versionWatch
Web pixel events strip name, email, phone and address unless the app is approved for protected customer data10 Dec 2025Anything reading email from pixel events receives blanksPassed
Additional scripts stop on non-Plus Thank you and Order status pages26 Aug 2026Tracking comes from Customer EventsPassed

In words: the version clock is the live risk — 2025-10 retires on 16 October and 2026-04, the worker's version, on 16 April 2027. Two data-layer changes are already in effect: since 10 December 2025 web pixel events carry no customer name, email, phone or address unless the app holds approved protected customer data access, and since 26 August 2026 additional scripts no longer run on non-Plus Thank you and Order status pages.

ChangeDateExposureStatus
Customer Match uploads moved from the Google Ads API to the Data Manager API1 Apr 2026Already on the Data Manager APIPassed
Offline conversion uploads left the Google Ads API15 Jun 2026Not usedPassed
ad_storage alone decides whether GA4 data reaches Google Ads; the Google Signals setting no longer does15 Jun 2026Consent signals are sent before any tag loadsPassed
Ads personalization settings move from GA4 to Google Ads; ad_personalization becomes the only controlLater 2026, undatedSignals already sent; confirm the Ads account setting matches when datedWatch
IP addresses the Google tag collects are encrypted and sent to the linked Ads accountLater 2026, undatedNo code change; re-read any privacy notice that describes IP handlingWatch
GA4 user deletion runs on Google's v1alpha admin APINo dateAlpha versions can change without the usual noticeWatch

In words: three Google changes have already happened. Customer Match uploads moved to the Data Manager API on 1 April 2026, which CRM Sync already uses; offline conversion uploads left the Google Ads API on 15 June 2026, which CRM Sync does not use; and since 15 June the ad_storage consent signal alone decides whether GA4 data reaches Google Ads. Later in 2026, on a date Google has not announced, ads personalization settings move from GA4 into Google Ads with ad_personalization as the only control, and tag-collected IP addresses are encrypted and sent to the linked Ads account. CRM Sync already sends ad_personalization and ad_user_data; when Google sets the date, the Google Ads account's setting should be checked against the signal. The GA4 user deletion used for privacy requests runs on an alpha API, so a deletion that starts failing should be diagnosed with the GA4 deletion preflight first.


Just past the window

DateChangeExposureStatus
1 Dec 2026Returns and subscription apps need Customer Account API sign-in to keep Built for Shopify statusDoes not applyClear
1 Jan 2027Expiring offline tokens required for all public appsExchange ready; per-shop migration uncheckedAction
1 Jan 2027POS Liquid receipt templates converted automaticallyNo POS receiptsClear
1 Mar 2027Script tags stop running on storefrontsNone usedClear

In words: on 1 December 2026 returns and subscription apps need Customer Account API sign-in for Built for Shopify status, which does not apply to CRM Sync. On 1 January 2027 expiring offline tokens become mandatory for all public apps, and POS Liquid receipt templates are converted automatically. On 1 March 2027 script tags stop running on storefronts.


What it costs to leave these alone

Left aloneWhat it looks like from outsideSeverity
Flow extensions on 2025-01Flow runs keep succeeding on a substituted version; a field that changed shape returns empty, and nothing errorsMedium, silent
A shop not migrated to expiring tokensAdmin calls for that one shop fail from 1 January while every other shop worksHigh, dated
Ads personalization dated without noticePersonalized audiences shift because the Ads setting disagrees with the consent signalMedium, undated
GA4 alpha API changesA privacy deletion records that Google was not instructedLow; the record says so

In words: the most expensive item is a shop left on a non-expiring token, because it fails on a known date and only for that shop. The quietest is the Flow extension version, which never errors — it returns different data with a success status.

What this does not claim. It covers the five topics raised and the Shopify and Google changes found dated inside the window. It is not a full audit of every Shopify changelog entry, and the React Native finding reflects what Shopify has published about its own apps, not a guarantee about its SDKs.

What to do next

  1. Bump both Flow extensions off 2025-01 to a supported API version and deploy the app. Owner: platform engineer.
  2. Confirm every installed shop holds an expiring token during October. Owner: platform engineer.
  3. Scan the storefront for script tags that are not yours. The table above says CRM Sync uses none, and that answers whether this app breaks — not whether the store does. A shop can carry script tags installed by apps years ago, including apps since uninstalled, and every one of them stops running on 1 March 2027. Two steps, because they answer different questions:
  4. Capture a HAR on a live product page and a cart page, and list every third-party script that actually loads. See How to capture a HAR. This tells you what is running.
  5. Query the shop's script tags through the Admin API and compare the two lists. This tells you how each one is delivered — the same reviews, loyalty or upsell widget may arrive via a script tag, a theme app embed, or a line someone pasted into the theme years ago. Only the first has a death date; only the last is invisible to both the app list and the vendor.

Anything appearing in both lists needs the vendor asked a direct question: have you moved to a theme app embed, and by when. A vendor that has already migrated will say so immediately. A vendor that has not is a dated outage on someone else's schedule. Owner: platform engineer with the merchant's app owner.

  1. Match the Google Ads personalization setting to the ad_personalization signal when Google dates the change. Owner: Revenue BA with the Google Ads account owner.
  2. Replace the last REST call with the GraphQL shop query. Owner: platform engineer. Optional.
  3. Review again on 1 January 2027, when 2027-01 releases and three months before 2026-04 retires. Owner: platform engineer.

Sources

Platform pages are primary; agency and news articles are secondary and were used only for dates a platform page did not state.

Shopify

Google

Secondary


Platform dates read 16 September 2026. Dates marked "later 2026" are unannounced by the platform, not estimated here. This is a change brief, not a certification.