Understanding the New Per‑Customer Request Limit for Shopify’s Customer Account API

Shopify now caps each customer to 3,000 Customer Account API requests per minute per store, shared across all apps. Learn what changed, who it impacts, and how to add retry logic so your integrations stay reliable.

Understanding the New Per‑Customer Request Limit for Shopify’s Customer Account API
6 sections

Shopify’s latest developer update introduces a per‑customer rate limit for the Customer Account API: 3,000 requests per minute per store, shared across every app that touches the endpoint. While most merchants won’t notice a difference, developers need to be aware of the new throttle and ensure their apps gracefully handle HTTP 429 responses. In this post we break down the change, identify who’s affected, and give you actionable steps—complete with code examples—to keep your integrations running smoothly.

What Changed

Previously, the Customer Account API was governed solely by a cost‑based rate limit (the “API points” system). The new rule adds a hard cap of 3,000 requests per minute per customer on a given store. This limit is shared across all installed apps that make Customer Account API calls. When the combined traffic from any number of apps exceeds the threshold, Shopify returns a 429 Too Many Requests response with a THROTTLED error code and a Retry‑After header indicating how long to wait before retrying.

Who Is Affected

*Developers*: Any private or public app that calls the Customer Account API—whether to fetch customer details, manage addresses, or update account information—must respect the new per‑customer limit. The limit is agnostic to which app makes the request; it aggregates traffic across all apps on the same store for a single customer.

*Merchants*: Store owners typically won’t need to take action because everyday buyer traffic (browsing, checkout, account updates) stays far below 3,000 calls per minute per customer. However, merchants who run custom storefronts, heavy‑use loyalty programs, or third‑party integrations should be aware that a sudden spike (e.g., a flash sale that triggers many account‑related calls) could trigger throttling.

How the New Rate Limit Works

  • Counting Requests – Every HTTP request that hits any Customer Account endpoint (e.g., /accounts/{customer_id}, /account_addresses) increments the per‑customer counter.
  • Shared Bucket – The 3,000‑request bucket is shared among *all* apps on the store for that customer. If App A makes 2,000 calls and App B makes 1,200 calls in the same minute, the limit is exceeded and the next call receives a 429.
  • Retry‑After Header – When throttled, Shopify includes a Retry-After header (seconds). Your app should pause for at least that duration before retrying.
  • Cost‑Based Limit Still Applies – The existing points‑based limit runs in parallel. You could hit a 429 for either reason, so handling both cases with the same retry logic is recommended.
  • Implementing Robust Retry Logic

    The safest way to stay compliant is to detect 429 responses, read the Retry-After value, wait, and then retry. Below is a simple JavaScript example using the Fetch API that you can adapt to Node, Ruby, or any language you prefer.

    javascript

    function fetchWithRetry(url, options = {}) {

    return fetch(url, options).then(response => {

    if (response.status === 429) {

    const retryAfter = parseInt(response.headers.get('Retry-After'), 10) || 1;

    console.warn(Rate limited. Retrying after ${retryAfter}s);

    return new Promise(resolve => setTimeout(resolve, retryAfter * 1000))

    .then(() => fetchWithRetry(url, options));

    }

    return response;

    });

    }

    // Usage example

    fetchWithRetry('https://your-store.myshopify.com/api/2024-07/customer_accounts/12345', {

    method: 'GET',

    headers: { 'X-Shopify-Access-Token': process.env.SHOPIFY_TOKEN }

    }).then(res => res.json()).then(data => console.log(data));

    Best Practices to Stay Well Below the Limit

    *Batch Requests* – Where possible, consolidate data needs into a single call rather than many small calls per customer.

    *Cache Customer Data* – Store frequently accessed information (e.g., name, email) in a short‑term cache and refresh it only when needed.

    *Event‑Driven Updates* – Trigger account‑related API calls only on meaningful events (order placed, address change) instead of on every page view.

    *Monitor Throttling* – Log every 429 response and its Retry-After value. Over time you’ll see patterns and can adjust call frequency before hitting the limit.

    *Graceful Degradation* – If a retry still fails after a few attempts, show a friendly error to the shopper and optionally fall back to a static UI state rather than breaking the checkout flow.

    Conclusion & Next Steps

    Shopify’s per‑customer request cap is a protective measure that, for most stores, will operate behind the scenes without impact. Developers who already have retry handling for other Shopify APIs are already in good shape; just extend that logic to watch for HTTP 429 on the Customer Account API and respect the Retry-After header.

    If you’re building a high‑traffic app or a custom storefront that heavily interacts with customer accounts, audit your request patterns today, add the retry snippet above, and set up monitoring for throttling events. Staying proactive now will keep your shoppers’ experience seamless and your app compliant with Shopify’s evolving platform limits.

    Ready to tighten up your integration? Start by adding the retry helper to your codebase, run a load test on a sandbox store, and let us know in the comments how it performed!

    Tags
    Sources

    Related Articles

    Cart Mutations Now Reject Unconfirmed Writes in POS UI Extensions (2026‑10)

    Cart Mutations Now Reject Unconfirmed Writes in POS UI Extensions (2026‑10)

    Shopify POS UI extensions using the 2026‑10 API now reject cart mutations when the platform can’t confirm a write. Learn what changed, who’s impacted, and how to update your code to handle rejections gracefully.

    October 7, 20264 min
    POS UI Extensions Now Return Accurate Percentage Values for Discounts

    POS UI Extensions Now Return Accurate Percentage Values for Discounts

    Shopify POS 11.15 updates the Discount.amount field for percentage discounts, aligning it with the Cart API contract. Developers must adjust their POS UI extensions to treat the amount as a percentage, not a monetary value.

    October 7, 20264 min
    How to Downgrade Your Shopify App’s Access Scopes from Write to Read

    How to Downgrade Your Shopify App’s Access Scopes from Write to Read

    Learn how Shopify’s new appDowngradeAccessScopes mutation lets developers replace unnecessary write permissions with read‑only scopes, who is impacted, and step‑by‑step actions to implement the change.

    October 7, 20264 min
    Unlock Deep Insights: Analyze Purchase Orders Directly in Shopify Analytics

    Unlock Deep Insights: Analyze Purchase Orders Directly in Shopify Analytics

    Shopify now lets merchants review, export, and track purchase order data with three new analytics reports. Learn what’s changed, who it impacts, and how to start using the tools today.

    October 6, 20264 min