Shopify Has No Phone Login and Indian D2C Feels It Most
Your customer placed a COD order using a phone number. You confirmed it over WhatsApp. Your courier called them on it. Every meaningful interaction in that transaction ran through a phone. Then they try to sign into their account and Shopify asks for an email address and sends a six digit code there. For a large share of Indian shoppers, that is a channel they barely use, and it is the point where returning customers quietly stop returning.
What Shopify actually supports
Worth stating precisely, because there is a lot of wishful thinking about this. Shopify's documented sign-in methods for customer accounts are:
- Email one-time code. The customer enters an email address and receives a six digit verification code. This is the default.
- Shop Pay. If Shop Pay is active, customers can sign in with their Shop credentials and saved passkeys.
- Google and Facebook. Social login through those accounts.
- Your own identity provider. On Shopify Plus, connecting an OpenID Connect provider replaces the default sign-in experience.
SMS and phone number authentication are not on that list. There is no native option to sign a customer in with a code sent to their mobile number.
That is not an oversight so much as a reflection of where Shopify's centre of gravity sits. In most of its largest markets, email is a reliable identifier. In India it often is not.
Why this hits Indian stores harder
Three things compound.
Phone is the identity. A shopper's mobile number is how they are known to their bank, their delivery apps and their government ID. Email is frequently something created once for a signup and rarely opened afterwards.
COD makes email optional in practice. A customer completing a cash on delivery order has not needed a working email address at any point in the purchase. If checkout captured one, it may be typed carelessly or not monitored, which means the login code goes to an address that functionally does not exist.
WhatsApp is the real inbox. Order confirmations, delivery updates and support all run through it for many brands, which trains customers to ignore email entirely. Our notes on WhatsApp for Shopify stores in India cover how much of the relationship lives there.
The result is an account system that assumes a channel your customer does not use, on top of a purchase flow that never required it.
What this actually costs you
Not lost orders at the front end. Guest checkout still works and a first purchase completes fine.
The cost is repeat purchase. Customers who cannot sign in cannot see their order history, cannot reorder easily, cannot self-serve a return, and cannot access store credit if you issue it. Every retention mechanism you have built behind an account is unavailable to them, and they will not tell you. They will just buy the way they did the first time, or not at all.
It also raises support volume in a way that is hard to attribute. "I cannot log in" tickets get resolved individually rather than being recognised as a systemic mismatch.
Option one, make the paths that exist actually work
Before anything custom, use what is available.
Turn on Shop Pay sign-in. Shop Pay is widely used in India and a customer with saved Shop credentials and passkeys skips the email code entirely. This is a settings change.
Turn on Google sign-in. Almost every Android user in India has a working Google account tied to the phone in their hand, and it is far more likely to be live than the email they typed at checkout. This is the single highest-return change on this page for most stores.
Fix email deliverability anyway. Email remains the default path, so if your sender domain is unauthenticated you are compounding the problem. We covered the diagnostic order for that separately.
For a lot of Indian D2C stores, Google sign-in plus working email delivery closes most of the gap at zero development cost. Do that before considering anything below.
Option two, capture email properly at checkout
Less exciting and genuinely effective. If the account system runs on email, then the quality of the email you collect determines whether accounts work at all.
Look at what proportion of your COD orders have an email address that has ever been opened. If your email platform reports engagement, that number is available and is usually worse than expected. Where it is poor, the fix is upstream at checkout and in your post-purchase messaging, giving customers a reason to provide an address they actually read.
Option three, an identity provider on Plus
This is the only route to genuine phone based sign-in, and it comes with a hard gate.
On Shopify Plus you can connect your own OpenID Connect identity provider, which replaces the default sign-in experience. An identity provider you control can authenticate however you like, including by phone and SMS, and then present that identity to Shopify.
Two honest caveats. It requires Shopify Plus, so for most brands reading this the question becomes whether phone login alone justifies the move to Plus, and usually it does not on its own. And it is a real implementation with real requirements, including a one second response budget on your provider's endpoints. Our piece on customer accounts and identity providers covers what that involves.
Where it does make sense is when phone identity is one of several reasons, alongside enterprise sign-on, a mobile app sharing the same accounts, or a membership platform that already owns customer identity.
What we would not do
Build a custom phone login in front of Shopify on a non-Plus store. You can construct something that collects a phone number, sends an OTP and then tries to establish a Shopify session, and it will be fragile, unsupported, and will break the next time Shopify changes the account flow. Multipass, the mechanism people reach for here, only works with legacy customer accounts, which are deprecated.
If phone login is genuinely business critical, that is a Plus conversation, not a workaround conversation.
Measure it before and after
This is the part that turns an opinion into a decision. Most stores discuss login friction without ever quantifying it, which is why it stays unfixed for years.
Three numbers are enough. Your returning customer rate, which is the outcome you actually care about. The share of orders placed by customers with an account versus guest checkout, which tells you how many people are even attempting the account path. And your support contacts mentioning login, counted for a month rather than estimated from memory.
Take those three, enable Google and Shop Pay sign-in, fix your sender authentication, then look again after a full purchase cycle for your category. If nothing moves, you have learned something useful and cheaply. If returning customer rate moves even slightly, the arithmetic on further work becomes easy, because retention compounds in a way that acquisition does not.
What you should not do is skip the baseline. Without it you will never know whether the change worked, and the next person who suggests a login project will be arguing from instinct exactly as you are now.
Does Shopify support phone number login for customers?
No. Customer accounts sign in with an email one-time code, Shop Pay with passkeys, or Google and Facebook social login. On Shopify Plus you can connect your own identity provider, which is the only supported route to authenticating by phone.
Can I use OTP on mobile instead of email on Shopify?
Not natively. The one-time code goes to email. An SMS based code requires an external identity provider connected to customer accounts, which is available only on Shopify Plus.
What is the easiest fix for Indian stores?
Enable Google sign-in and Shop Pay sign-in, then make sure your sender domain is authenticated so email codes actually arrive. That combination costs nothing and covers most customers, because nearly every Android user has a live Google account even when their email address is dormant.
Do customers need an account to buy?
No. Guest checkout works regardless, so this does not block first purchases. It affects repeat purchase, order history, self-serve returns and store credit, which is where the revenue impact sits and why it is easy to miss.
Is it worth moving to Plus just for phone login?
On its own, almost never. Plus is a significant cost and phone sign-in is one feature. It becomes reasonable when identity requirements stack up, such as a mobile app, a loyalty platform and enterprise buyers all needing to share one login.
Talk to us about your customer login
Free review. Email hello@exactwhy.com with subject "Phone login" and tell us your plan, whether Shop Pay and Google sign-in are enabled, and roughly what share of your orders are COD. We respond within 4 hours with what will actually move your repeat purchase rate. For most stores that is two settings and a DNS record, not a project.
Paid work, Rs 40,000 to Rs 1.5 lakh. Enabling and testing every available sign-in path, fixing email deliverability, improving how email is captured at checkout, and measuring the change in returning customer rate.
Ongoing Shopify development, Rs 20,000 to Rs 50,000 a month. For brands where retention depends on the account layer working properly.
The mismatch here is real and it is not going away on its own. What is fixable today is making sure the paths that do exist are switched on and working, because most Indian stores we look at have left two of them turned off.