Shopify's new bot auth: Pay for the platform, then manage their infra
I’m posting this here because I need to vent about my fiat-mine job.
I tried posting this on the r/Shopify subreddit, but it was auto-removed because I don’t meet their arbitrary karma requirements. Gotta farm those internet points before you’re allowed to complain about legitimate technical issues…
Here, I can just pay to post 😅
Anyway, I knew this was coming because Ahrefs sent out a notification a while ago. But yesterday I got my first failed crawl on a client store 🤬
Honestly, I’m trying to understand the logic behind this.
My client already pays for the platform and for Ahrefs. Now, if I want to crawl their storefront, I’m forced to implement cryptographic signatures. And the burden is entirely on me to manage it.
Here’s where it gets retarded:
- One Signature Per Subdomain: For every market, I need to generate a new signature.
- Arbitrary Expiration: Signatures expire after a maximum of 90 days.
- No Renewal: I can’t just “renew” signatures. I need to start the entire process over from scratch.
- Three Headers Per Domain: For every tool, I need to attach three separate HTTP headers (Signature-Input, Signature, and Signature-Agent).
It’s an operational headache for zero added value on our end. It’s pure rent-seeking: offloading their infrastructure overhead onto the users footing the bill.
Rant over.
Write a comment