Shopify Just Throttled the Bots. Here's What Hydrogen Storefronts Need to Sign — and Why It Matters Now.
On May 7, 2026, Shopify quietly rewrote how AI agents and crawlers are allowed to talk to your store.
Stricter rate limits are now live on the Storefront API and on Shopify-hosted online store pages.
Bots and agents that don't sign their requests get the strictest tier.
To get higher limits, operators need to sign with Web Bot Auth.
This is a small changelog entry with a big downstream effect — especially if you run a Hydrogen storefront and you've been counting on AI traffic to grow.
What Actually Changed
Shopify's announcement is short. The implications are not.
1. New default: bots get throttled
Any bot or agent hitting the Storefront API or Shopify-hosted pages without a signed identity is now subject to the strictest rate limits Shopify offers.
Unsigned crawler? Throttled.
Unsigned LLM scraping product data? Throttled.
Unsigned agent following a checkout link? Throttled.
This is the first time Shopify has split "real bots" from "anonymous traffic that looks like a bot" at the platform layer.
2. The way out: sign with Web Bot Auth
Web Bot Auth is an emerging IETF draft. It lets a bot operator publish a public key, then sign each HTTP request with the matching private key.
Shopify is recommending Cloudflare's implementation guide as a reference — but you don't have to enroll with Cloudflare to use the protocol. The signature is the only thing that matters.
If your agent signs every request, Shopify can verify the identity and lift the throttle.
3. Higher tiers exist, but you have to ask
Even with Web Bot Auth, default limits aren't unlimited. Operators that need more headroom — large-scale crawlers, commerce agents serving millions of users — fill out a request form for higher access tiers.
4. Merchants get a free pass on their own store
If you want to crawl your own Shopify store (SEO audits, product feed jobs, internal tools), the admin now ships with ready-to-use Web Bot Auth signatures. No DIY cryptography required.
Why This Lands Differently for Hydrogen Storefronts
If you're building on Liquid, this is mostly an external concern — your bot traffic is whatever ChatGPT, Perplexity, and Google decide to send.
If you're building on Hydrogen, you're on both sides of the wire.
You're a publisher and a consumer
A Hydrogen storefront fetches the Storefront API at request time, on Oxygen edge nodes, in front of every shopper.
That's normal traffic — you're not the bot. Your storefront identifies itself with your Storefront API token, and that's a different rate-limiting lane.
But the moment you wire agentic features into your storefront — a chat interface, a product search agent, a Storefront MCP integration — you're calling Shopify on behalf of someone else. That traffic looks more like a bot, and it's now in scope.
If those agent calls aren't signed, they share the same throttle bucket as random scrapers.
Agentic Storefronts default-on changes the math
Shopify activated Agentic Storefronts for all eligible US merchants on March 24, 2026.
AI-attributed orders are up 11x year-over-year. AI traffic is up 393%.
That traffic isn't shoppers in browsers — it's agents talking to your storefront. ChatGPT Shopping. Perplexity. Google AI Mode. Microsoft Copilot.
Those agents are exactly the population Shopify is now putting on stricter limits unless they sign.
The agents that sign get reliable access to your catalog. The ones that don't get throttled — and your products quietly disappear from their answers.
You can't control what every agent operator does.
You can make sure the agents you ship — the ones running inside your Hydrogen routes, your MCP server, your product search — sign their own requests.
What to Do This Week
A short, action-required checklist for any team running a Hydrogen storefront with AI surfaces:
1. Inventory every "bot-shaped" call your stack makes
Anywhere a script, cron, or agent talks to Shopify on behalf of a non-human:
- Catalog sync jobs against the Storefront API
- Agent integrations on Storefront MCP / Catalog MCP
- Any internal crawler hitting your Shopify-hosted pages (legacy /products/ URLs, theme assets, sitemap)
- Webhooks that loop back into Storefront API queries
These are the surfaces at risk of being throttled.
2. Decide which need Web Bot Auth signatures
Not every backend call does. Your normal Hydrogen route handlers run with a Storefront API token — that's already a separate identity.
But anything that loops through your domain like a bot — sitemap crawlers, agent retrieval, third-party indexers you've contracted — needs to be signed.
3. Implement Web Bot Auth
The protocol is a public/private key pair plus an HTTP signature header. The Cloudflare guide walks through the keys and the signature flow.
For a Hydrogen storefront, the cleanest place to land this is in a route module middleware (now stable in Hydrogen 2026.4) — sign outbound agent requests at the edge, log unsigned requests for audit.
4. If you're a merchant, grab Shopify's prebuilt signatures
For first-party crawls of your own store — internal SEO tools, product feed validators — Shopify ships ready-made Web Bot Auth signatures in the admin under SEO / crawl your store. No reason to roll your own.
5. Apply for higher tiers if you need them
If you operate a commerce agent at scale, file the higher access form before traffic hits the limit, not after.
The Bigger Pattern
Web Bot Auth fits a clear pattern Shopify has been shipping for the last six months:
- Storefront Catalog MCP now implements UCP (Apr 22) — agent traffic gets a standard protocol
- Agentic Storefront default-on for all US merchants (Mar 24) — agent traffic gets a default surface
- Hydrogen 2026.4 mandatory Storefront API proxy (Apr 9) — storefront traffic gets a single chokepoint
- Web Bot Auth + stricter rate limits (May 7) — agent traffic gets identity
Shopify is building a clear lane for AI-mediated commerce, with proper auth, proper rate limits, and proper attribution.
Storefronts that don't move with that lane lose share to ones that do.
This isn't optional infrastructure work. It's the table stakes for being on the AI shopping graph in 2026.
The Bottom Line
Web Bot Auth is small in the changelog and big in practice.
If your Hydrogen storefront wants reliable access from AI agents — yours and everyone else's — sign your bot traffic now, audit your crawler surfaces, and move ahead of the throttle.
Need this audited or implemented end-to-end on a production Hydrogen storefront? The Weaverse team takes on Hydrogen builds and rescue projects — from full storefronts to single-route signing middleware. Senior engineers, competitive quotes, no agency overhead. Talk to us →
Sources
- Shopify Developer Changelog — Bots and agents should identify themselves via Web Bot Auth (May 7, 2026)
- Shopify API Limits — Storefront rate limits
- IETF Draft — Web Bot Auth Architecture
- Cloudflare Docs — Verified Bots / Web Bot Auth implementation guide
- Shopify Help Center — Crawling your store
- Weaverse — Every Shopify Hydrogen Storefront Is Now an AI Agent Endpoint
- Weaverse — Hydrogen 2026.4 Breaking Changes
- Weaverse — Storefront Catalog MCP → UCP Migration



