Allow Restricting Direct Public Access to Commerce API Endpoints
Commerce endpoints are currently directly accessible, and there is no native option to restrict access while still allowing intended use of the Admin Console, Storefront APIs, and integrations.
We would like the ability to limit direct access to Commerce endpoints through controls such as IP allowlists, trusted networks, VNets, or Private Endpoints.
This would help organizations reduce exposure of publicly accessible endpoints and better align with internal security and compliance requirements, without impacting normal Commerce functionality.
4
votes