- Card‑deposit endpoint now requires a Shopify‑issued mTLS client certificate for all deposit calls (enforced Oct 15 2026).
- Apps using customerPaymentMethodCreditCardCreate or Update must obtain and present the certificate or deposits will be rejected; apps only using customerPaymentMethodRemoteCreate are unaffected.
- Obtain the certificate via shopify‑mtls‑partnerships@shopify.com, present it on /sessions calls, and rotate it annually before the 1‑year TTL expires.