Aptum Checkout Protection

Support

Contact

Email support@aptum.ai. Please include your store's myshopify domain, the approximate time, and the exact message the buyer saw. Do not send buyer addresses, payment details, access tokens or your signing key.

We reply within one business day (Monday to Friday, US Eastern time). If quote checkouts are being blocked when they should not be, mark the email URGENT or contact support@aptum.ai. We aim to respond the same business day.

Setting up

  1. Install the app from its Shopify App Store listing. Shopify asks you to approve one permission: managing checkout validation rules.
  2. In the app, choose Create or repair checkout rule. The checklist shows when the rule is installed, enabled and set to block checkout if it cannot run.
  3. For production, enter a signing key. Your quoting system must sign quotes with the same key.
  4. Use Create a test checkout link in the app to see an allowed checkout and a blocked one.

What buyers see

This quote is priced for delivery to the quoted address. To ship somewhere else, contact us for a shipping review and a replacement checkout before paying.The buyer entered a delivery address different from the quoted one. Issue a new quote for the new address.
This quote has expired. Contact us for an updated quote before paying.The quote's valid-until date has passed. Issue an updated quote.
This quote checkout could not be verified. Contact us for a new checkout link.The quoted destination or its signature was altered, or the signing key differs from the quoting system's. Check the key, then issue a new link.
This quote checkout is missing its delivery details. Contact us for a new checkout link.The checkout carries a quote reference but no signed destination. The quoting system did not add all attributes.
Enter the quoted delivery address to complete this quote checkout.The buyer tried to pay without a delivery address.

Turning protection off

In Shopify admin, go to Settings → Checkout → Checkout rules and turn off the app's rule. Quote checkouts will then accept any address, so have someone review addresses by hand while the rule is off.

For quoting-system developers

The rule acts only on checkouts that carry all of these cart attributes. A Shopify draft order's custom attributes, or a cart permalink's attributes[…] parameters, both work:

The destination is JSON: ["v1", address1, address2, city, state code, ZIP5, "us"]. Each part is trimmed, has its internal whitespace collapsed to single spaces, and is lowercased. The signature is lowercase hex HMAC-SHA256 of that exact string using the signing key, or plain SHA-256 when no key is set (test mode only). Only US delivery addresses are supported.


Aptum, LLC · 12604 Hallstatt Dr, Manor, TX 78653