← All articles

October 5, 2026 · Muhammad Rehan · More by Muhammad Rehan

Checkout Validation Functions Gain Billing Address and PO Checks

API 2026-04 adds billing address and PO number fields to Shopify's Cart and Checkout Validation Functions, closing a client-side compliance gap.

Checkout Validation Functions Gain Billing Address and PO Checks — ASSOSIATIX Journal

Shopify's Cart and Checkout Validation Functions can now see billingAddress and poNumber on the function input graph, as of API version 2026-04. Two new checkout field targets ship alongside: $.cart.billingAddress.{field}, covering any standard address subfield, and $.cart.poNumber. Previously, both fields returned null when a Validation Function tried to read them; they still return null in any Shopify Function context outside Cart and Checkout Validation.

What the change actually adds

The input graph addition means a validation function running during checkout can now inspect the buyer's billing address and any purchase order number entered on the order — not just cart lines or shipping details. The two field targets give the function a place to attach an error: a billing-country check can surface its message directly against the billing address field in checkout, and a missing-PO-number check can surface against the PO number field itself, rather than as a generic cart-level error.

Shopify names two use cases directly: blocking prohibited billing countries, and requiring PO numbers for B2B orders. Both are compliance patterns that wholesale and B2B storefronts need, and both previously had no first-class way to be enforced inside a Validation Function.

Why this matters more than it looks

Before this change, a merchant who wanted to reject orders from embargoed billing countries, or require a PO number on every wholesale order, had to build that logic into a client-side UI extension — checkout's buyer-facing surface. That works for a buyer following the intended flow, but it's enforcement at the wrong layer: a UI extension doesn't run as part of order creation itself, and anything that bypasses or modifies the client-side checkout experience can skip it.

A Cart and Checkout Validation Function runs as part of checkout processing on Shopify's side, independent of what the buyer's client does or doesn't render. Moving billing-country and PO-number checks into a function means the rule is enforced at the same layer that decides whether an order can be created — not just suggested on the surface the buyer sees.

What this doesn't change

Shopify is explicit that this is additive: existing functions keep running unchanged, and validating against the new targets is opt-in. There's no breaking change to plan around. For teams already building compliance rules into B2B checkout, the work now is deciding which of these two targets to wire a function to, and what the input graph's billingAddress and poNumber fields let that function actually check.

Sources

Enterprise & Shopify Plus

ASSOSIATIX works on this every day. See our Shopify Plus & Enterprise Commerce Solutions service

$./start-project.sh

READY TO BUILD
WHAT'S NEXT?

Tell us where you are and where you want to go. We'll help you choose the right path—storefront, system, product, or a focused growth sprint.