Shopify Freezes Script Tags on October 1. Audit Your Apps Now, Not in February.
Shopify published the deprecation on August 24, 2026. Two dates matter. On October 1, 2026, the scriptTagCreate and scriptTagUpdate mutations start returning a user error, and the REST ScriptTag resource rejects POST and PUT. On March 1, 2027, Shopify stops injecting script tags into storefronts at all. The deprecation applies to every API version, including older ones, so an app pinned to a 2022 release gets no extra runway.
The recommendation
Run a script tag audit on every store you operate this week, before October 1. Pull your active script tags, map each one back to the app that created it, and get a written answer from each vendor on whether they have shipped a theme app extension or a web pixel replacement. Anything tracking-related gets migrated first, because that is the failure mode that costs you money silently instead of loudly.
The audit is cheap. The scriptTags query and the scriptTagDelete mutation keep working past both deadlines specifically so you can inventory and clean up. Nothing about this requires a developer sprint. It requires someone to actually look.
Why most merchants will skip this and regret it
The October 1 change freezes writes, not execution. A script tag that an app installed in 2023 keeps firing on October 2. That is the trap. There is no error banner in your admin, no email, no drop in the dashboard. Everything looks fine, so the task slides to a backlog and resurfaces in late February when it is a scramble instead of an afternoon.
Two things break before March, though, and both are easy to miss:
Reinstalls and app updates. If you uninstall and reinstall an app after October 1, or the vendor needs to repoint a script at a new CDN path, the write fails. You end up with a stale script or no script at all, and the app’s own UI will often still report itself as connected.
New store launches. Standing up a second storefront, a regional store, or a wholesale channel after October 1 means any legacy-app dependency simply will not install its script. If your launch checklist assumes app parity across stores, that assumption is now wrong.
What actually uses script tags
Script tags are how the previous generation of apps injected JavaScript into a storefront without touching theme code. In a typical DTC stack, the usual suspects are review widgets, chat and support bubbles, popup and email capture tools, affiliate and partner tracking pixels, upsell and bundling apps, loyalty widgets, and older analytics or conversion tags.
Note the split. This deprecation covers script tags with a display_scope of online_store. Order status page script tags were already handled under an earlier deprecation and have stopped working. So if you are running a checkout or post-purchase tracking setup that predates checkout extensibility, you may already be losing data and not know it.
The math on what going dark costs
Tracking is where this gets expensive, because broken attribution does not show up as broken. It shows up as your paid channels quietly reporting worse, and you reacting to numbers that are wrong.
Take a brand doing $400,000 a month in DTC revenue with $80,000 a month in paid media at a blended 4.0 ROAS. Say an affiliate or conversion script loaded by a legacy app stops firing, and 15% of conversions go unattributed. Reported ROAS drops to 3.4 on identical actual performance. If your media buyer responds the way most do, by pulling budget from the campaigns that now look worst, you cut spend on profitable inventory and the real revenue follows the reported revenue down.
Run the other direction too. If the broken script is an affiliate tracker, your partners stop getting credited, and the ones driving real volume churn to a competitor who pays them correctly. Reacquiring a productive affiliate costs more than the migration would have.
Both scenarios are illustrative, not measured, but the shape holds: the cost is not the downtime, it is the decisions you make on bad data while the downtime is invisible.
The migration path
Two replacements, and the right one depends on what the script does.
App embed blocks replace script tags for anything that renders on the storefront. The vendor ships them inside a theme app extension, and then someone has to turn them on in the theme editor. That last part is the gap merchants fall into. The vendor can do their half perfectly and the feature is still off on your store until a human activates it. If you run multiple themes, or you duplicate a theme for seasonal edits, every copy needs the block enabled.
Web pixels replace scripts that only collect analytics or conversion data. These need no merchant action once the vendor implements them, which makes them the better outcome where they apply.
For the apps you actually depend on, the real question is not whether Shopify gave enough notice. It is whether your vendor has shipped. Ask directly, and ask for a date.
Your audit this week
- Inventory. Query active script tags on each store. Record the src URL for each one, since that is usually what identifies the app behind it.
- Map to apps. Match each script to an installed app. Anything you cannot trace is a strong candidate for deletion, especially leftovers from apps you uninstalled without a clean removal.
- Delete the dead weight.
scriptTagDeletestill works. Orphaned scripts from churned apps are pure page-weight cost and a site speed drag you are paying for right now. - Rank what is left by revenue impact. Anything touching tracking, attribution, or checkout goes first. Cosmetic widgets go last.
- Email each vendor. One question: have you migrated to a theme app extension or web pixel, and if not, what is the date? Treat a non-answer as a no.
- Verify activation. For vendors who have already migrated, confirm the app embed block is actually enabled in your live theme. Do not assume.
- Re-verify after every theme change. Add app embed block confirmation to whatever checklist you use before publishing a theme.
Where this fits in the broader Shopify cleanup
This is not an isolated deadline. Shopify has been methodically removing the escape hatches that let apps and merchants inject arbitrary code into storefronts and checkout, and each one lands the same way: announced early, ignored, then urgent. Script tags are the current one. If you have been deferring a general app audit, this is the forcing function. Most stores we look at are carrying three to five apps nobody uses, each with a script still loading on every page view.
Do the audit for the deadline. Keep the speed and the shorter app bill as the bonus.
If you want a second set of eyes on your Shopify stack, or you are running multiple storefronts and want this handled once across all of them, book a call and we will walk your setup with you.
More in Shopify & DTC
See all Shopify & DTC insights →