— 2026 — AUG 21, 2026 —

Fixing Shopify Customer Account API Errors in Hydrogen

The Customer Account API works cleanly once it is set up correctly, and produces a small set of confusing errors when it is not. The confusing part is that most of them are session handling problems wearing the costume of an authentication problem, so developers spend hours on OAuth configuration when the actual fault is a cookie that was never written. Here are the four that come up most and what each one is really telling you.

How authentication actually works here

Worth being clear about the model before debugging it, because the errors make more sense afterwards.

The Customer Account API uses OAuth 2.0. Confidential clients running server side use the standard authorization code flow with a client secret. Public clients use Proof Key for Code Exchange to guard against interception of the authorization code. Shopify is the identity provider and hosts the login page.

In Hydrogen, createCustomerAccountClient wraps this, and it requires a session to persist the access and refresh tokens. Hydrogen ships with cookie session storage by default, though you can substitute another implementation.

That dependency on the session is where nearly everything goes wrong.

Error one, the session state does not match the state parameter

The most common one and the most misleading, because it reads like an OAuth misconfiguration.

OAuth uses a state parameter to tie the redirect back to the request that started it. Your app generates it, stores it in the session, and checks it when the customer returns. If the value coming back does not match what is in the session, the check fails.

In practice that almost always means the session was not configured correctly or was not passed into createCustomerAccountClient, so the state was never stored where the check looks for it.

There is a second cause worth knowing because it is genuinely hard to spot. The state can be created in one browsing context and checked in another. A login started inside an in-app webview, then completed in the system browser, involves two different cookie jars. The second context has no session containing the state, so the comparison fails even though nothing is misconfigured. If this only reproduces for customers arriving from Instagram or another in-app browser, that is the cause.

Error two, the customer is logged in and then is not

A customer signs in, everything works, and a few requests later they are anonymous again. No error, just an inconsistent session.

This is usually a missing session commit. Checking whether a customer is logged in can trigger an access token refresh. That refresh produces new tokens, but they only persist if the session is committed to the Set-Cookie header at the end of the loader or action. Skip the commit and the refreshed tokens exist for exactly one request and then vanish.

The rule is simple: commit the session at the end of any loader or action that performs a logged-in check, not only the ones that obviously write data. This one is easy to miss because a read looks like it should not need a write.

Error three, cookie too large

Hydrogen's default cookie session storage puts session data in a cookie, and cookies have a size limit that browsers enforce. Accumulate enough in the session, tokens plus cart state plus whatever else your app decided to keep, and you exceed it.

The symptom is a request failing on size rather than an authentication error, which sends people looking in the wrong place.

Two fixes. Reduce what you store in the session, keeping identifiers rather than whole objects. Or move to a different session storage implementation so the cookie holds only a session identifier and the data lives server side. If you are storing anything substantial per customer, the second option is where you will end up eventually, so consider it early rather than after an incident.

Error four, third-party cookie warnings on the login page

Chrome reports third-party cookies on Shopify's hosted login page, associated with hCaptcha and set with SameSite=None; Secure. Developers see this in the console during testing and reasonably worry about future browser changes to third-party cookies.

This one is not yours to fix. It is on Shopify's hosted page and involves their bot protection. Note it, do not build around it, and do not let it derail your debugging, because it is unrelated to session problems in your own application.

Getting local development working

A category of its own, because a lot of time is lost here before any real work starts.

OAuth needs the redirect URI to match exactly, which means your local environment has to be reachable at a URL registered with Shopify. That usually means a tunnel, and the URL must be registered rather than assumed. Tunnels that issue a new URL on every restart create a fresh mismatch each time, which is why the first error above appears constantly during setup and then stops once the environment stabilises.

If a login flow works in production and fails locally, check the redirect URI before anything else.

A debugging order that saves time

  • Confirm the session is created and passed into the customer account client. Most state mismatches end here.
  • Confirm you commit the session at the end of loaders and actions that check login status.
  • Check the redirect URI matches exactly, especially locally.
  • Check what you are putting in the session if you see size errors rather than auth errors.
  • Reproduce in a normal browser before trusting a failure seen only in an in-app webview.

Four of those five are session handling. That is the pattern worth internalising: when Customer Account API authentication behaves strangely, suspect the session before suspecting OAuth.

Test the contexts your customers actually use

The gap between a working local build and a working production one is usually browsing context, and it is not something a normal test pass catches.

Your customers do not all arrive in a clean desktop browser. A large share arrive from an in-app browser inside Instagram, Facebook or WhatsApp, particularly in markets where social is the primary discovery channel. Those environments have their own cookie handling, and some of them hand off to the system browser partway through a flow, which is exactly the condition that breaks the OAuth state check.

Safari's tracking prevention is worth a pass too, since it treats cookies more aggressively than Chrome and will surface problems your Chrome testing never shows.

Build a short list of real contexts, desktop Chrome, mobile Safari, and at least one in-app webview, and run the full login through each before release. Finding a webview problem in testing costs an afternoon. Finding it after a campaign launch costs a day of failed logins from your highest-intent traffic.

What does session state does not match the state parameter mean?

The OAuth state value returned from Shopify does not match what your session holds. Usually the session was not configured or not passed to createCustomerAccountClient, so the state was never stored. It can also happen legitimately when login starts in one browsing context, such as an in-app webview, and completes in another with a different cookie jar.

Why does my customer keep getting logged out in Hydrogen?

Most often a missing session commit. A logged-in check can trigger a token refresh, and the refreshed tokens only persist if the session is committed to the Set-Cookie header at the end of the loader or action. Without that they last one request.

How do I fix cookie too large errors?

Store less in the session, or replace Hydrogen's default cookie session storage with an implementation that keeps data server side and puts only an identifier in the cookie. The error is about size limits rather than authentication, even though it usually surfaces during login work.

Does the Customer Account API work on all Shopify plans?

The API itself is the authentication path for headless storefronts and is not the same as connecting your own identity provider, which is Plus only. Confirm your specific requirements against current documentation before scoping, since the plan boundaries around customer accounts have moved more than once.

Should I use a custom session storage from the start?

If you are building anything beyond a simple storefront, yes. Cookie storage is fine for tokens alone and becomes a size problem as soon as you keep meaningful state per customer. Switching later is a refactor, so it is cheaper to decide early.

Get help with your headless build

Free review. Email hello@exactwhy.com with subject "Customer Account API" and describe the error plus where it happens. We respond within 4 hours. Most of these have a specific cause and we would rather tell you what it is than sell you a project.

Paid development, Rs 60,000 to Rs 2 lakh. Authentication implementation in headless builds, session architecture that survives scale, and testing across real browsing contexts including in-app webviews.

Ongoing Shopify development, Rs 20,000 to Rs 50,000 a month. For teams running a headless storefront who want an escalation path.

If you are still deciding whether headless is right at all, our Hydrogen and Liquid comparison is the better starting point, and our custom development costing covers how we scope this kind of work.

Parth Sojitra
Parth Sojitra

Other Blogs

2026
Returns and Exchanges That Do Not Destroy Your Margin
Aug 25, 2026
Parth Sojitra
2026
Six Shopify Changes That Already Broke Something on Your Store
Aug 24, 2026
Parth Sojitra
2026
Selling Overseas From India on Shopify Without Duty Surprises
Aug 23, 2026
Parth Sojitra
2026
Why Your Shopify Inventory Is Wrong and How to Find Out
Aug 22, 2026
Parth Sojitra
2026
The Shopify Login Popup Is Gone and What Replaces It
Aug 20, 2026
Parth Sojitra
2026
Shopify Has No Phone Login and Indian D2C Feels It Most
Aug 20, 2026
Parth Sojitra
2026
Why Your Shopify Customers Never Get Their Login Code
Aug 20, 2026
Parth Sojitra
2026
Best Way to Upgrade Shopify Legacy Customer Accounts
Aug 20, 2026
Parth Sojitra
2026
Shopify Legacy Customer Accounts and Where Auth0 Fits In
Aug 20, 2026
Parth Sojitra
CAREER
Why I Traded Cricket at Fifteen for Freedom at Twenty Five
Aug 20, 2026
Parth Sojitra
2026
How to Read a Shopify Quote Before You Sign Anything
Aug 20, 2026
Parth Sojitra
2026
What Actually Breaks When You Connect Shopify to an ERP
Aug 19, 2026
Parth Sojitra
2026
Your Shopify Inventory Buckets Changed on 5 August 2026
Aug 14, 2026
Parth Sojitra
2026
Why Your Shopify Checkout Validation Needs to Move to Functions
Aug 13, 2026
Parth Sojitra
2026
Your Shopify Store Became an AI Agent Endpoint on 5 August
Aug 12, 2026
Parth Sojitra
2026
How to Rebuild What Shopify's Checkout Deadline Removes
Aug 11, 2026
Parth Sojitra
2026
What Breaks on Shopify's August 26 2026 Checkout Deadline
Aug 06, 2026
Parth Sojitra
2026
How to Cut COD RTO Losses on Shopify India in 2026
Aug 06, 2026
Parth Sojitra
2026
Shopify Analytics Setup for Growth 2026 (What Matters)
Aug 05, 2026
Parth Sojitra
2026
Shopify to Shopify Plus Migration in 2026 (Upgrade Guide)
Aug 04, 2026
Parth Sojitra
2026
Best Shopify Agencies for B2B and Wholesale in India in 2026
Aug 03, 2026
Parth Sojitra
2026
Shopify Speed Optimization Services Cost India 2026 Compared
Aug 02, 2026
Parth Sojitra
2026
BigCommerce to Shopify Migration in 2026 (Complete Cost Guide)
Aug 01, 2026
Parth Sojitra
2026
Shopify Theme Customization Cost India 2026 (Real Pricing)
Jul 31, 2026
Parth Sojitra
2026
BFCM 2026 Emergency Prep (120 Days Left, Critical Checklist)
Jul 30, 2026
Parth Sojitra
2026
Shopify Landing Page Design Cost India 2026 (Real Numbers)
Jul 29, 2026
Parth Sojitra
2026
Shopify Plus vs Advanced (Which One Do You Need in 2026)
Jul 28, 2026
Parth Sojitra
2026
Shopify Custom App Development Cost India 2026 (Real Numbers)
Jul 27, 2026
Parth Sojitra
2026
Shopify SEO Services Cost in India 2026 (Pricing Guide)
Jul 21, 2026
Parth Sojitra
2026
WooCommerce to Shopify Migration India 2026 (Cost Guide)
Jul 21, 2026
Parth Sojitra
2026
Book a Free Shopify Strategy Call in 2026 (What Happens)
Jul 20, 2026
Parth Sojitra
2026
Shopify Store Redesign Cost in India in 2026 (Real Numbers)
Jul 19, 2026
Parth Sojitra
2026
What Is the Best Solution After Magento End of Life in 2026
Jul 18, 2026
Parth Sojitra
2026
What Is the Best Solution After Adobe Commerce End of Life
Jul 18, 2026
Parth Sojitra
2026
Shopify Emergency Support in India (24-Hour Response Guarantee)
Jul 18, 2026
Parth Sojitra
2026
GST Setup for Indian Shopify Merchants in 2026 (Complete Guide)
Jul 17, 2026
Parth Sojitra
2026
BFCM 2026 Prep Booking Window Is Closing (133 Days Left)
Jul 17, 2026
Parth Sojitra
2026
WhatsApp Business API for Shopify India in 2026 (Complete Guide)
Jul 16, 2026
Parth Sojitra
2026
Adobe Commerce End of Support 2026 (What Merchants Must Do)
Jul 15, 2026
Parth Sojitra
2026
Shopify Audiences vs Meta and Google Ads for DTC Brands in 2026
Jul 15, 2026
Parth Sojitra
2026
Shopify Subscription Commerce in 2026 (What Works for Brands)
Jul 14, 2026
Parth Sojitra
2026
Shop Pay in India 2026 (What Actually Works for Indian Merchants)
Jul 13, 2026
Parth Sojitra
2026
Best Shopify Agency for Beauty Brands in India in 2026
Jul 12, 2026
Parth Sojitra
2026
Shopify Flow Automation Recipes for Indian DTC Brands in 2026
Jul 12, 2026
Parth Sojitra
PLUS FEATURES
Shopify Winter 2026 Editions Predictions (What Ships in January)
Jul 11, 2026
Parth Sojitra
2026
Shopify Premium Website Development Company India 2026 Guide
Jul 10, 2026
Parth Sojitra
2026
Shopify Sidekick in 2026 (What It Does for Real Merchants)
Jul 10, 2026
Parth Sojitra
2026
Best Shopify Agencies in Ahmedabad in 2026 (Verified List)
Jul 10, 2026
Parth Sojitra
2026
Shopify Store Not Converting (Free 48-Hour Diagnostic Below)
Jul 10, 2026
Parth Sojitra