Shopify's new bot auth: Pay for the platform, then manage their infra

I’m posting this here because I need to vent about my fiat-mine job.

I tried posting this on the r/Shopify subreddit, but it was auto-removed because I don’t meet their arbitrary karma requirements. Gotta farm those internet points before you’re allowed to complain about legitimate technical issues…

Here, I can just pay to post 😅

Anyway, I knew this was coming because Ahrefs sent out a notification a while ago. But yesterday I got my first failed crawl on a client store 🤬

Honestly, I’m trying to understand the logic behind this.

My client already pays for the platform and for Ahrefs. Now, if I want to crawl their storefront, I’m forced to implement cryptographic signatures. And the burden is entirely on me to manage it.

Here’s where it gets retarded:

  • One Signature Per Subdomain: For every market, I need to generate a new signature.
  • Arbitrary Expiration: Signatures expire after a maximum of 90 days.
  • No Renewal: I can’t just “renew” signatures. I need to start the entire process over from scratch.
  • Three Headers Per Domain: For every tool, I need to attach three separate HTTP headers (Signature-Input, Signature, and Signature-Agent).

It’s an operational headache for zero added value on our end. It’s pure rent-seeking: offloading their infrastructure overhead onto the users footing the bill.

Rant over.

https://stacker.news/items/1505034

Write a comment
No comments yet.