Hey folks - thanks for the reports here.
We’ve confirmed a detection bug affecting CartDiscountCodesUpdate.discountCodes warnings. Calls served on Storefront API versions before 2026-01 can trigger the warning even when they correctly supply discountCodes, including []. This could be the reason for some of these flags you’re seeing.
For enforcement, @Donal-Shopify’s September 9 clarification says deprecated calls made by a third party using your public Storefront token don’t, by themselves, result in enforcement against your app. Unusual token activity can prompt a review, but that’s an outreach step rather than automatic delisting. Your own implementation still needs to supply discountCodes on 2026-01 and later.
API Health doesn’t currently provide a self-serve breakdown of the originating store or third-party caller, and Support can’t disclose those stores’ identities. I’ve submitted a feature request for additional attribution tooling as well.
Under the standard version schedule, older requests are expected to be served as 2026-01 from October 16 at 15:00 UTC. If you see new detections after that, please reach out in an authenticated Partner Support conversation so we can review those examples.
Hope this helps!