$ the-wire · showcase
Hydrogen moves consent to CTA async, dropping Server-Timing and legacy cookies
By RepoJournal · Filed · About Shopify · Composed from the cited sources · methodology
Hydrogen's 2026.4.x patch train hands consent and visitor-token ownership to Shopify's Customer Privacy API, a breaking change for classic Hydrogen storefronts that read tracking values themselves.
Use CTA async consent for classic Hydrogen Shopify/hydrogen
Classic Hydrogen now configures CTA and the privacy banner so consent initialization happens asynchronously before analytics reads tracking tokens. The PR's author notes the goal is to give "consent and visitor tokens one owner" instead of splitting coordination between Hydrogen's own consentManagement request and the Customer Privacy API.
@shopify/hydrogen-react@2026.4.4 Shopify/hydrogen
by shopify-github-actions-access[bot]
In hydrogen-react, getTrackingValues() no longer scans performance entries for Server-Timing headers. It reads from the Customer Privacy API's __internal getters, then a module-level cache of the last consentManagement response body, and the deprecated JavaScript-visible _shopify_y and _shopify_s cookies are gone, so any code reading them directly needs updating.
@shopify/hydrogen@2026.4.6 Shopify/hydrogen
by shopify-github-actions-access[bot]
The main hydrogen package picks up the same async consent initialization: the separate consent query and cache writes, plus Server-Timing collection and forwarding, are removed. This is a breaking change for storefronts that depended on those headers or on Hydrogen-owned consent caching.
skeleton@2026.4.7 Shopify/hydrogen
by shopify-github-actions-access[bot]
skeleton@2026.4.7 is a patch release that only updates its @shopify/hydrogen dependency to 2026.4.6, carrying the consent changes downstream for anyone on the skeleton starter.
Bump Shopify/theme-tools packages Shopify/cli
The CLI bumped @shopify/theme-check-node 3.29.0 to 3.29.1 and @shopify/theme-language-server-node 2.22.2 to 2.22.3, and separately reordered its automated testing task to fix recent flaky tests before chasing coverage gaps.
Action items