Customer accounts

Buyer accounts on your storefront, without building auth.

Storefront sign-up and sign-in with order history, saved cards, addresses, invoices, returns, and subscription self-service, kept apart from your merchant API.

Everything a returning buyer expects

Turn on customer accounts and your storefront gets:

  • Sign-up and sign-in, email verification, password reset, and sign-out everywhere.
  • Order history, with cancelling an order and requesting a return.
  • Saved cards — add, set a default, remove — and saved addresses.
  • Invoices, with PDF downloads.
  • Subscriptions the buyer can pause, resume, or cancel themselves.

Fewer “where’s my order?” emails, and fewer support tickets for things a buyer could do in ten seconds.

Drop-in, or your own design

The @usethrottle/auth React package ships ready-made sign-in and sign-up pages and modals, a user menu, and an account dashboard covering orders, invoices, subscriptions, payment methods, addresses, and security — themeable and localizable. Prefer your own UI? Every piece is an API call.

Secure by design

  • Buyer accounts live on their own storefront API. A buyer’s session can never call your merchant API, and your merchant keys can’t act as a buyer.
  • Sessions rotate their tokens on every refresh; reusing a spent token signs out the whole session.
  • Sensitive actions such as removing a card ask for the password again.
  • Buyers can see their active sessions and revoke any of them.

Guests and imported customers welcome

A guest or an imported customer becomes an account through “forgot password”: they set a password and their past orders are already there. That’s also how customers come across from another platform, since passwords can’t be migrated.

Good to know

  • Accounts are switched on per application and environment, and production needs your storefront’s origins allowlisted.
  • Sign-in is email and password; social login and SSO aren’t available.
  • Buyers must verify their email before managing saved cards or subscriptions.