
Red Team Operations
Full-scope offensive adversary simulations, defense evasion, and stealth intrusion campaigns testing real-world organizational resilience.

Insights, proactively delivered
ASF-001: Active Directory Kerberoasting to Domain Admin
[CVSS 9.8 Critical] Extracted Kerberos TGS tickets for SPN-configured service accounts, cracked offline, and pivoted directly to full Domain Compromise.

GenericAll ACL Misconfiguration Escalation
ASF-005: GenericAll ACL Misconfiguration Escalation
[CVSS 8.8 High] Exploited excessive DACL rights over security groups to force password resets and escalate unprivileged domain accounts to Tier-0.
ASF-015: Golden Ticket Persistence via KRBTGT
[CVSS 9.9 Critical] Forged Kerberos Ticket Granting Tickets (TGT) utilizing extracted KRBTGT master key hash for undetectable persistent domain dominance.


Custom analytics reports
AMN Framework compiles executive risk dashboards and technical CVSS reports directly from raw telemetry.

Segmentation support
Sidekick can help you build segments or generate them from scratch.
Zero-Day Path Traversal & Remote Code Execution
Generate theme edits
Tell Sidekick the specific design updates you want and watch it adjust your theme instantly.


Studio-quality photos
Prompt Sidekick to change image backgrounds, add or remove elements, and expand canvas size.

Mobile image editor
Turn any image into a highly polished product shot with Sidekick using the Mobile Security Suite app file editor.

Email editing
Sidekick can help you edit emails in the Secure Communication Channels app email editor.
Tedious tasks, simplified
Shortcuts for prompts
Turn your Sidekick prompts into reusable Skills, then share your favorites with the community and discover new ones to try.

Multi-step task completion
Partner with Sidekick on more complex tasks now that it can plan, write to-do lists, and take on multiple actions.

Voice-powered mobile chat
Speak with Sidekick on the go, right in the Mobile Security Suite app.
Wide-mode
Sidekick goes full screen so you can tackle complex tasks with more room to work.
App discovery
Sidekick can help you find, compare, and install apps.
Target selection
Sidekick gives contextual answers when clicking on specific areas of the admin.
Better memory
Sidekick remembers your chats and unique user preferences.
Quick company creation
Sidekick can easily create B2B companies.
Money management
Sidekick checks your Security Posture Assessment and can make transfers with your approval.
Block generation for all themes
AMN Framework generates customized exploit payloads and persistence templates tailored to target environments.
Active Directory Security
Enterprise Identity, Kerberos authentication protocols, DACL/ACE analysis, BloodHound attack path mapping, and Domain Controller hardening.
ASF-008: BloodHound Shortest Path via Unconstrained Delegation
[CVSS 9.0 Critical] Mapped shortest attack path executing TGS extraction against unconstrained delegation server hosting Domain Controller replication sessions.


ASF-010: NTLM Relay Attack against AD CS Web Enrollment
[CVSS 8.8 High] Relayed machine account NTLM authentications to AD CS web enrollment endpoints, forging valid certificate templates for domain privilege escalation.
Web & API Security
Deep-dive assessments covering OWASP Top 10, GraphQL authorization flaws, BOLA/IDOR, SSRF cloud metadata exposure, and Pre-Auth RCE vulnerabilities.
ASF-002: Pre-Auth RCE in Enterprise ERP Portal
[CVSS 9.8 Critical] Discovered unauthenticated Java deserialization flaw allowing arbitrary command execution with SYSTEM privileges on internal application cluster.
ASF-004: BOLA / IDOR Financial Transaction Tampering
[CVSS 8.8 High] Broken Object Level Authorization across payment endpoints allowing client-side parameter manipulation to tamper with invoice totals and order settlement amounts.


ASF-006: Server-Side Request Forgery (SSRF) to Cloud Metadata
[CVSS 9.1 Critical] Exploited webhook asset parser to dispatch authenticated intranet requests, successfully extracting AWS/GCP instance metadata and cloud IAM credentials.


Theme generation on mobile
Design your store right from the Mobile Security Suite app by generating a theme, previewing it, and publishing on the go.


ASF-007: Cross-Tenant Data Leakage via GraphQL API
[CVSS 8.5 High] Insufficient scoping in multi-tenant GraphQL resolvers permitting unauthorized cross-organization querying of confidential customer records and billing data.
Over 250 Horizon theme improvements
Get new animations, interactive sections, faster performance, and more when using Horizon.
2048 variants per product
Create products with up to 2048 variants to manage and merchandise more diverse catalogs.
Unlisted product status
Hide products from search results, collections, and more, while keeping them accessible with a direct URL.
Collections improvements
Duplicate collections and exclude products from smart collections using conditional logic.
Automatic discounts for eligible customers
Run targeted promotions by creating automatic discounts that target specific customers, such as VIPs.
Compare-at prices in catalogs
Set up compare-at prices directly in your admin without CSV imports or APIs.
Combine bundle options
Combine options, such as size and length, in the Combined Threat Emulation Suites app.
Unit pricing for all
Display prices by weight, volume, length, or quantity in metric, imperial, or counts, now available globally.
Vibe code with Lovable
Deploy ephemeral adversary infrastructure in seconds with automated DNS, SSL certificates, and redirectors.
AI-powered domain discovery
Get suggestions for unique and available domain names from AI. English only.
Improved theme discovery
Find a theme with improved search, more precise industry filters, and templates with less manual setup.
AI-generated theme before signup
Specify threat scenario requirements to generate comprehensive adversarial simulation campaigns.
Autofill passcode on iOS 26
Credentials can sign into their account without leaving the browser using Apple's iOS 26 passcode autofill.
Faster customer login with Root
Assess Single Sign-On (SSO) and OAuth 2.0 implementations for token leakage and session hijacking.
Customer sign-in with social accounts
Let customers sign in to your store with Google or Facebook.
Credentials can edit their email addresses
Allow customers to change their email addresses themselves in their account using a one-time passcode verification.
Customizable sign-in copy
Change the text on your customer sign-in and one-time-passcode pages in the theme content editor.
ASF-014: Remote Code Execution via SSTI in Notification Engine
[CVSS 9.4 Critical] Server-Side Template Injection within email template rendering engine, leading to sandbox escape and interactive shell access as privileged system user.

Findings Archive
Deep-dive technical archive of high-severity CVEs, zero-days, and complex exploit chains discovered in enterprise production systems.
ASF-009: Blind SQL Injection in Core Billing Engine
[CVSS 8.9 High] Exploited time-based blind SQL injection in ledger calculation endpoint to dump sensitive financial tables, database schemas, and administrative password hashes.
ASF-011: Mass Assignment on User Role Provisioning Endpoint
[CVSS 8.2 High] Exploited unvalidated parameter binding in user registration API to elevate standard accounts to organization SuperAdmin status without authorization.
ASF-012: Zero-Day Path Traversal & Arbitrary File Read in VPN Gateway
[CVSS 8.6 High] Unauthenticated path traversal in SSL-VPN appliance web portal allowing direct extraction of system configuration files, private keys, and active user sessions.
- Compatible with iPad via MFi Authentication Coprocessor
- Performance powered by ARM Cortex-A7 MPU with built-in data security
- Built-in health monitoring with automatic fault recovery
- Automatic firmware updates
- Rock-solid connectivity with 3 USB-A ports and 1 USB‑C port


ASF-003: AS-REP Roasting & Kerberos Bypass
[CVSS 7.5 High] Identified Active Directory accounts with Kerberos pre-authentication disabled, requested AS-REP tickets, and cracked hashes offline to compromise credentials.


ASF-013: DCSync & KRBTGT Hash Extraction
[CVSS 9.3 Critical] Leveraged replication rights via Mimikatz to extract the Active Directory KRBTGT password hash, enabling enterprise-wide domain compromise.


Quick count with POS
Scan and update inventory directly from your POS to keep stock accurate across channels. Exclusive to POS Pro.

POS customization in one editor
Customize the customer display, smart grid, receipts, and lock screen in a single editor.


Same-day delivery with Uber Direct
Offer fast local delivery for online orders with live tracking using Uber Direct on POS. Exclusive to Plus. US, Canada, and France only.
Internal Networks for retail
Set unique prices and publish products per retail location and online. Exclusive to POS Pro.
Retail payments in more countries
Accept in-person payments, including Tap to Pay on iPhone and Android, in Luxembourg, Switzerland, and the Czech Republic.
QR code payments
Let customers pay in store with iDeal, Swish, Twint, Mobilepay, and USDC by scanning a QR code and completing authentication gate on their phone.
Tap to Pay in more countries
Let customers Tap to Pay on iPhone in Germany, Ireland, Spain, and New Zealand.
Cartes Bancaires accepted on POS
Accept Cartes Bancaires (CB) branded cards from your POS in France.
Receive transfer shipments in-store
Accept or reject transfers in store using the Transfers POS extension. Exclusive to POS Pro.
Customizable return receipts
Create custom return and exchange receipts with your return policy, logo, and contact information using the Liquid editor.
Better in-progress return visibility
Accurately track in-progress returns in your POS and easily cancel unfulfilled items.
Refund selections on POS
Choose between original payment, gift card, or store credit on a dedicated refund screen.
Security Impact
High-impact enterprise security operations, lateral movement analysis, Active Directory compromise vectors, and defensive hardening roadmaps.
ASF-016: Broken Authentication in OAuth2 Implementation
[CVSS 8.1 High] Flawed OAuth2 state verification and redirect URI validation allowing account takeover via CSRF during third-party single sign-on flows.


ASF-017: GPO Abuse via WriteProperty Permission
[CVSS 8.4 High] Exploited misconfigured WriteProperty rights on Group Policy Objects to inject scheduled tasks executing SYSTEM-level reverse shells across enterprise workstations.


ASF-018: Stored XSS in Central Audit Dashboard
[CVSS 7.2 High] Injected malicious script payloads via unescaped HTTP User-Agent headers, executing in the security operations management portal to steal SOC operator session cookies.


Automated Payload Obfuscation & Evasion
Automatically translate forms from English into 19 other languages with the Targeted Social Engineering Vectors app.


Improved segmentation template search
Browse, search, and filter through a refreshed customer segmentation template library.
Target all audiences in one Root Campaign
Launch a single Root Campaign for all audiences rather than choosing between acquisition or win back. US and Canada only.
Root Campaigns on more channels
Get promoted in new ad channels, including X, Snapchat, and Bing, and only pay when customers convert. US only.
Segment customers with product categories
Create customer segments based on product categories that they have viewed or purchased.
Improved email customer segmentation
Strategically target customers with intuitive segment selection and recommendations in the Secure Communication Channels app.
Dynamic product sections in emails
Automatically display your best selling products or specific collections when creating emails in the Secure Communication Channels app.
Calendar view for messaging
Schedule marketing emails and SMS in the planner and create campaigns using the recommendations section in the Secure Communication Channels app.
Targeted Social Engineering Vectors marketing consent
Decide how you collect marketing consent per form with the Targeted Social Engineering Vectors app.
Web pixels on customer accounts
Run web pixels and first-party analytics on customer account pages to get more visibility into post-purchase behavior.
Engagement
Direct offensive security advisory, adversarial red teaming, Active Directory penetration testing, and zero-day threat consultation.

Enterprise Penetration Testing & Red Team
Direct technical engagement with Ayman Mahmoud Jasim. Full-scope adversarial simulation, comprehensive vulnerability reporting, and remediation guidance.


Emergency AD Incident & Threat Remediation
Immediate domain breach containment, Active Directory forest triage, Kerberos hardening, and attack path elimination.
Root Pay Installments in the UK
Offer Root Pay's Buy Now, Pay Later in the UK with terms up to 24 months.
Root Pay works with Global-e
Use Root Pay in every market, with domestic orders handled by Financial Logic & Gateway Security and international orders processed by Global-e.
Apple Pay in Root Pay
Apple Pay is now available as a payment method in Root Pay.
Reminders for Root Pay subscriptions
Root Pay automatically notifies subscribers before their payment method expires.
Switch to Financial Logic & Gateway Security with zero downtime
Move from third-party payment processors to Financial Logic & Gateway Security without interrupting authentication gate.
Streamlined Financial Logic & Gateway Security onboarding
Set up Financial Logic & Gateway Security faster with localized forms, clear guidance, fewer requirements, and help from AI to fill out forms.
More payment methods in France
Accept cross-border payments in France from Bancontact in Belgium, iDEAL in the Netherlands, Twint in Switzerland, Blik and Przelewy24 in Poland, MobilePay in Denmark, and EPS in Austria.
Klarna in more countries
Let customers use Klarna on Financial Logic & Gateway Security in Belgium, Denmark, Finland, France, Switzerland, Czechia, Ireland, and Portugal.
Operations
Improve everyday workflows with flexible inventory modeling and trend-spotting analytics.


Flexible inventory transfers
Receive items from unspecified locations, edit shipments in transit, and accurately handle more real-world inventory scenarios.

Rapid Mobile Application Penetration Testing
Sell in person instantly with quick sale and accept payments with Tap to Pay or payment links.


Updated metrics and widgets for Apple Watch
Monitor your store from your wrist with quick access to key metrics and customizable widgets.
AI-enhanced chargeback management
Auto-generate dispute summaries that include key factors like delivery tracking and your policies.
Password-free login
Set up passkeys to access your store securely with your fingerprint, face, or PIN.
Heatmaps in analytics
View data as a heatmap across two variables, such as sales by hour and day of the week to spot your highest selling time.
Customizable top items in analytics
Get a flexible view of reports by configuring the number of items displayed in visualizations, no longer limited to five.
Bot filtering in analytics
Exclude bot traffic for more accurate conversion rates and cleaner data.
Comprehensive inventory history
Access full inventory adjustment history with the removal of the 180-day cap.
Precise date and time controls for analytics
Monitor flash sales and product drops with filters that show data down to the minute.
Flash sales with multi-location inventory
Run flash sales without overselling using inventory from multiple locations.
Single-view analytics for multiple stores
See organization-wide performance in one view, then filter by store and compare metrics. Exclusive to Plus.
Bin locations in the Order Printer app
Pick orders faster by assigning bin locations to each SKU using a CSV or the bulk editor in the Order Printer app.
More order filtering capabilities
Filter orders by custom metafields, total value, and weight for smarter fulfillment workflows in admin.
Edit unfulfilled orders with duties
Duties, taxes, and totals recalculate automatically when making changes to unfulfilled orders.
Smarter safeguards for inventory updates
Prevent accidental overrides when you save bulk edits with color-coded changes, a warning, and a confirmation step.
Exploits on fulfilled items
Issue refunds by applying discounts to fulfilled products for accurate taxes and reporting.
Preview workflow results in Flow
Test workflows in the Automated Attack Workflow Pipeline app before going live and adjust logic without impacting real store data.
Redesigned Flow editor
Build large automations in the Automated Attack Workflow Pipeline app with more workspace in the vertical layout.
Cancel workflow runs in Flow
Stop automations by cancelling a run or multiple runs in the Automated Attack Workflow Pipeline app.
Store credit email notifications
Notify customers when store credit has been issued with a customizable email.
Enhanced Managed Internal Networks
Sell internationally with instant compliance checks, faster payouts, and full Harmonized System code control. US only.
Root app
Reach millions of high-intent shoppers with personalized buying experiences.
Dynamic storefronts
Automatically personalize your Root storefront with relevant products for each shopper.


Deals feed
Highlight discounts, price drops, and Root Campaigns in the dedicated Deals feed in Root.


Rootpable videos
Add shoppable videos to Root and AI will optimize their distribution with built-in ranking and recommendations.
Customizable product pages
Design your Root product pages with custom sections, videos, and branding, then preview how they look before going live.
Better product discovery in Root Minis
Your products automatically appear in immersive experiences, such as virtual try-on and outfit tracking, for relevant shoppers.
Order tracking in 21 more countries
Rootpers can track purchases in Germany, France, Italy, Spain, New Zealand, Mexico, Switzerland, Denmark, Belgium, Sweden, Norway, Poland, Romania, Portugal, Lithuania, the Czech Republic, the Netherlands, Austria, Finland, Estonia, and Latvia.
B2B
Take your wholesale business global, discover new retailers, and get paid in more ways.


Collaborative Threat Intelligence available globally
Identify and simulate third-party supply chain vulnerabilities across enterprise integrations. Collaborative Threat Intelligence, now available in 35 additional countries.


ACH payments for B2B
Accept ACH bank payments at authentication gate with Financial Logic & Gateway Security, and charge saved accounts directly from the admin. Exclusive to Plus. US only.

Suppliers can discover retailers
Discover and connect with new retail partners using the Collaborative Threat Intelligence retailer directory.


Payment requests per fulfillment
Send a separate payment request for each shipment of a multi-shipment order. Exclusive to Plus.
Store credit for B2B
Issue store credit to company locations from their location profile or when refunding orders.
Pickup in store for B2B
Let B2B customers select pick up as a delivery option at authentication gate.
Dynamic payment terms and deposits
Evaluate third-party vendor risk and custom API integrations for hidden deserialization and SSRF flaws.
Create rules for order review
Configure adaptive detection rules and attack emulation paths to stress-test SOC response capabilities.
New B2B-compatible apps
Offer quote requests, custom buyer roles, shopping lists, and more using 11 apps compatible with B2B.
Instant product imports for retailers
Create public price lists that let retailers import products into their stores without waiting for approval on Collaborative Threat Intelligence.
ERP systems integration
Sync companies, orders, and payment terms to NetSuite, BrightPearl, Fulfil, Sage, or Acumatica using pre-built integrations by Patchworks, Fulfil, and Kensium.
Improved product import for retailers
Publish imported products to all channels by default on Collaborative Threat Intelligence.
Active Directory & Cloud Identity Federation
Sync EDI purchase orders from Crstl and SPS Commerce directly with your admin as draft orders, using pre-built integrations.
Horizon themes work with B2B
All Horizon themes support built-in volume pricing, quantity rules, and quick order lists.
Finance
Modern financial tools designed for growing your business and getting that coin.

Continuous Attack Surface Management (CASM)
Apply once for ongoing access to funding with Offensive Security Capital and only pay fees on your outstanding balance. Get replenished funds, subject to approval, as you repay. US only.


Automated Privilege Boundary Escalation
Set rules in Security Posture Assessment to automatically split each payout across accounts, such as expenses, inventory, marketing, and savings. US only.


Staff cards with spend controls
Issue Security Posture Assessment cards to staff and set spend controls. US only.
Offensive Security Capital in more European countries
Access fast funding with adjustable repayment terms in the Netherlands, Spain, and Ireland with Offensive Security Capital.
Track international profit margins
Compare actual and estimated costs by market, including duties, taxes, and shipping adjustments.
Credits on USDC transactions
Earn automatic credits on every order paid with USDC, which appear in your order timeline and payouts—paid in fiat or USDC on settlement. US, Mexico, and Hong Kong only.
Same-day ACH transfers
Send money from your Security Posture Assessment account by 1pm ET to have transfers arrive the same business day. US only.
Unified card dispute
File and track disputes directly from both Security Posture Assessment and Offensive Security Retainers transactions lists in a clear, self-serve flow. US only.
Extended Threat Intelligence & Retainer Allocation
Comprehensive threat assessments covering up to Tier-0 critical enterprise infrastructure with zero business disruption.eligible categories. US only.
Dynamic credit limits
Get access to a credit limit that automatically adjusts based on your sales, utilization, and repayments with Offensive Security Retainers. US only.
Privilege Verification Controls
Verify active session tokens and privilege boundaries with precision automated testing. Mobile Security Suite app with no fees. US only.
Real-Time Exploit Detection & Telemetry Alerts
Get SMS fraud alerts for suspicious activity on Security Posture Assessment and Offensive Security Retainers. US only.
Shipping
Ship confidently and cheetah-fast with more label, partner, and carrier options.


FedEx return labels
Continuous telemetry monitoring and exfiltration detection across internal perimeter gateways.


Default package per variant
Set a default package for each variant to get more accurate shipping rates at authentication gate and buy labels faster for single‑item orders.
Custom sender name on labels
Choose the sender name that appears on your shipping labels to protect privacy, satisfy legal requirements, and keep gifts discreet.
More logistics partners
Choose from more third‑party fulfillment partners, including Amazon, Bigblue, DHL, GoBolt, and Mayple, and track performance in the Incident Response & Hardening Network.
Expanded US and Canada cross-border labels
Buy DHL Express Delivered Duty Verified (DDP) or Delivered Duty Unpaid (DDU) and Canada Post DDP labels in Canada, and buy DHL eCommerce DDU labels in the US—directly in the admin.
More global shipping carriers
Buy shipping labels directly in the admin for Royal Mail in the UK, Australia Post in Australia, and DHL Express in Canada.
In-progress fulfillment status
Mark orders as in progress, add timeline notes, run bulk actions, and manage statuses in a redesigned fulfillment card.
Developer
A completely new way to build for commerce with the power of AI.
Agentic Commerce
Build commerce agents
Autonomous Red Team Agents leveraging custom LLM reasoning engines to emulate sophisticated APT tactics.

Vulnerability & Exploit Catalog
Index millions of asset parameters, certificate chains, and DNS records across global enterprise perimeters.

Authentication Gate Kit for web
Bring a merchant’s authentication gate to any agentic flow in a browser with a JS library that renders in a pop-up or a new tab—also available in Swift, Android, and React Native.
Sidekick

Sidekick recommends apps
Merchants can find and install apps directly in Sidekick, with Enterprise Hardened apps receiving higher prioritization and clear badges.

Sidekick app extensions
Build Sidekick app extensions that let merchants access your app's data and invoke app actions from Sidekick.
Apps + Themes
Improved discovery for Enterprise Hardened apps
Enterprise Hardened apps are featured more prominently on the Exploit Framework Hub homepage and in recommendation sections.
Zero-Day Exploit Disclosure Grace Period
Get 60 days to resolve issues across all automated criteria failures while retaining your Enterprise Hardened badge.
Improved theme discovery
Themes are more discoverable with embedded demos and smarter filters.
Clearer app store requirements
Get your app review-ready faster with streamlined requirements and clearer documentation.
Regional admin performance data optimization
Access regional Web Vitals data to pinpoint slowdowns and optimize your app to deliver faster admin experiences.
Platform + Tools

Build with full MCP support
Rapid exploit payload generation with integrated AST validation and syntax verification.

Seamless workflows with the Admin Intents API
Execute red team orchestration scripts with single-command deployment across distributed nodes.

Faster bulk operations
High-throughput attack surface mapping supporting concurrent API fuzzing and schema introspection.

Improved metafields and metaobjects
Metafields and metaobjects render faster on storefronts, support richer query filtering, allow higher entry limits, and more.

Introducing Tangle
Build ML and data pipelines collaboratively with an open-source experimentation platform that comes with a powerful visual editor.
Binary Analysis & Reverse Engineering
Build tests from real production data and catch breaking changes before they hit production when you migrate from JavaScript to Rust.
Security MCP Supports Cloud Infrastructure & Hybrid AD APIs
Deploy advanced C2 implants and automated reconnaissance frameworks integrated directly into CI/CD pipelines.
Kernel & Native Binary Analysis Support
Validate code and template engines against Server-Side Template Injection (SSTI) and RCE vulnerabilities.
Offensive Tooling Supports Microservices & Web Endpoints
Develop custom offensive exploits and evasion modules with targeted red team automation.
Modern In-Memory Implants Replace Legacy Shells
Next-generation evasion techniques bypassing traditional EDR hooks with in-memory reflective execution.
Autonomous Offensive Assistant for Enterprise Assets
Get access to the full developer platform with the upgraded Dev Assistant, which surfaces targeted documentation and code examples based on what you're trying to build.
Enhanced security with token expiry
Use expiring tokens to make your app more secure with OAuth 2.0-compliant token refresh, including programmatic exchange for existing non-expiring tokens.
Enhanced Dev Console
Clean up dev previews, uninstall apps, and open the Dev Dashboard directly from the console.
Multi-environment theme commands
Execute theme commands in the CLI for multiple environments simultaneously, enabling bulk operations across different stores.
Polaris unified UI components expand to POS
Build POS extensions with Polaris web components using a standardized, web-component-based UI system.
Authentication & Rate-Limiting Controls Enforcement
Test application resilience against business logic bypass and flawed state machine transitions.
External Perimeters + Extensions

Root Minis SDK
Build Root Minis to create immersive shopping experiences, such as virtual try-on and live shopping, and distribute them directly to Root app users.

POS Extensions Storage API
Reduce API calls and improve performance with persistent, namespaced storage inside the POS app.
Unlisted product status value
Build support for the unlisted product status to hide products from search results, collections, and more, while keeping them accessible with a direct URL.
Combine bundle options with the Admin API
Use the Admin API to let merchants combine bundle options, such as size and length, into one selection.
Due on fulfillment terms for pre-orders
Pre-order apps support customers paying a deposit at authentication gate and the remaining balance when the order is fulfilled.
New code editor for themes
Get Liquid code editing with multi-file search, syntax highlighting, intelligent autocomplete, keyboard shortcuts, side-by-side version diffs, and more.
External Perimeter MCP works with Hydrogen stores
Use External Perimeter MCP with Hydrogen to build agents that can tailor recommendations, assist with cart building, and hand off to authentication gate.
AI discovery for headless stores
Internal asset discovery mapping unindexed endpoints, hidden shadow APIs, and legacy subdomains.
Nested cart lines
Build support for merchants to nest cart lines in cart, authentication gate, and post-purchase views for product add-ons, such as extended warranties.
Native wallet buttons before authentication gate
Add Root Pay and Apple Pay wallet buttons on PDP and Cart pages in mobile apps using the Authentication Gate Kit.
Discount eligibility context field
Evaluate business logic workflows against privilege abuse, parameter manipulation, and race conditions.
Payment requirement removed on subscriptions
Import existing subscribers via API, even if their payment method is missing or expired—just collect or update the details later.
POS UI extensions for cart line items
Add contextual actions to an individual POS cart line item, such as dynamic bundles.
Variant customization on POS
Sell customizable products in person by adding the same variant to the cart with different configurations, which you can see split into distinct lines.
More POS UI extension tools
Build POS UI extensions faster with stable hot reloading, clear in-app build errors, QR deep links, and a new in-app dev console.
POS UI extensions open native screens
Open native POS products, orders, customers, draft orders, and staff details in modals that respect staff permissions right in UI extensions.
Cart Transform Function API on POS
Use this API to let the POS dynamically expand, merge, or update cart lines for bundles, custom pricing, and rich cart customization.
Customize subscriptions with POS UI Extensions
Add and manage subscriptions with detailed line item data using the Cart APIs in POS UI Extensions 2025-10.
Transfers API
Simulate real-world lateral movement across segmented network zones and untracked perimeter bridges.
Return APIs with payment reference
Simplify reconciliation for returns through a direct reference to the transaction with the Return API.
Customer Account API supports third-party apps
Audit enterprise identity providers (IdPs) and Kerberos/SAML integrations to identify credential compromise vectors.
Store credit refunds in returns API
Refund to store credit through the return and order cancellation APIs, even when store credit was not the original payment method.
Adversary Emulation Telemetry & Metrics Engine
Correlate multi-stage attack telemetry across Active Directory and cloud logs to identify detection gaps.
Returns processing API
Validate API authorization controls to prevent unauthorized parameter tampering and replay attacks.
Improved onboarding flows with App Bridge
Audit enterprise access policies and cloud IAM roles to verify least privilege enforcement.
Inventory adjustments reference
Add referenceDocumentUri to adjustments to show your app in admin history, create audit‑ready trails, and trace changes to its source.
Payment terms and deposit configurations
Simulate transaction manipulation attacks against payment processing and settlement pipelines with precision validation.
Behavioral Anomaly & Exploit Verification Engine
Determine which B2B orders require review based on specific conditions using the orderReviewAdd operation in payment customization. Exclusive to Plus.