Quick answer
Use Shopify’s Cart and Checkout Validation Function API when a business rule must actually prevent an invalid purchase. The Function runs on Shopify’s servers, checks the cart or checkout data you request, and returns targeted validation errors when the order does not meet the rule.
This is the right layer for rules a theme cannot reliably enforce: restricted addresses, quantity limits, B2B order rules, customer eligibility, incompatible cart contents, and similar conditions.
On this page
Why theme validation is not enough
A theme can warn the customer, disable a button, or prevent a form submission in the normal storefront flow. That can improve the experience, but it is not authoritative checkout enforcement.
Customers can reach checkout through accelerated checkout, custom storefronts, apps, or other supported paths. Shopify describes Cart and Checkout Validation Functions as the server-side mechanism for rules that must apply across checkout.
What the Function actually does
The Function receives only the fields requested in its input query. Your code evaluates those inputs and returns validation operations. When a condition fails, the Function returns an error message and a target indicating where Shopify should surface it.
That design is useful because the Function does not need to know everything about the cart. Ask only for the data the rule needs.
Good validation rules
Validation is a good fit when the answer is genuinely yes or no: may this cart proceed?
- Reject shipping or billing addresses that violate a restriction.
- Enforce product minimums, maximums, or multiples.
- Prevent an invalid combination of products.
- Apply B2B order minimums or company-location rules.
- Require a buyer or cart state before checkout can complete.
- Enforce purchase limits for scarce or regulated merchandise.
Bad validation rules
Do not use blocking validation for something that is only a suggestion. If the goal is “we would prefer the customer choose this option,” a warning or UI treatment is usually better.
Also do not turn a Validation Function into a large remote business application. Functions are deliberately constrained. Keep the rule small, deterministic, and based on the minimum data required.
Cart interaction vs. checkout completion
The validation input exposes buyer-journey context so a Function can understand whether it is running during cart interaction, checkout interaction, or checkout completion. That can matter when a rule should only block at a certain point.
Do not show a hard error earlier than necessary if the customer still has a normal path to fix the cart.
Target the error where it helps
A useful validation error tells the buyer what failed and what they can do next. Shopify supports targeted checkout errors as well as cart-level/global errors.
“Order invalid” is technically an error message, but it is poor UX. “This item cannot be purchased with a billing address outside the United States” tells the customer what needs to change.
Fail open or fail closed?
Decide what should happen when expected data is missing. For a legal or compliance restriction, missing required data may need to fail closed. For a merchandising convenience rule, blocking a valid customer because an optional metafield is blank may be worse than allowing the checkout.
This decision belongs in the business requirement before it belongs in code.
Know the compatibility limits
Validation Functions are broad, but not every Shopify surface has identical support. Shopify’s current compatibility table should be checked during implementation. For example, the current Function reference marks recurring subscription orders as unsupported even though cart and checkout validation is supported across many storefront and checkout surfaces.
Do not assume a validation that runs during the initial purchase will necessarily govern every later recurring-order event.
Keep configuration out of source code when merchants need control
If a merchant needs to change a threshold, eligible product, country list, or another rule without redeploying the app, store that configuration in an appropriate Shopify resource such as metafields and request it in the Function input.
Hard-coded values are fine for truly fixed rules. They are painful for operational settings that change every promotion or season.
A clean implementation sequence
- Write the rule in plain English.
- Identify the minimum Shopify data needed to evaluate it.
- Define the Function input query.
- Return no validation errors for a valid cart.
- Return a specific targeted error for an invalid cart.
- Test cart, checkout, and accelerated paths that the store actually uses.
- Test missing data and boundary values.
- Review the Function logs after deployment.
Common misunderstanding
Hiding or disabling checkout in the theme is not checkout validation. A real business rule should be enforced where Shopify processes the cart and checkout, not only where the theme happens to render a button.
How to test this
- Create one cart that should pass and one that should fail.
- Test the exact boundary: one below, at, and one above a quantity or value limit.
- Test missing customer, address, metafield, or company data where relevant.
- Test accelerated checkout if the store uses it.
- Confirm the error appears at a useful target and explains the fix.
- Confirm removing the invalid condition lets the buyer proceed immediately.
- Review current Shopify compatibility before assuming the rule covers subscriptions or every sales surface.

