--- url: https://developer.youcan.shop/changelog/customer-accounts.md --- Themes can render the customer account pages: login, register, password reset, account, orders and addresses. A `customer` object describes the logged in customer, and the storefront API has customer endpoints for login, logout and password recovery. *** # Objects * `customer` is available in every template and is nil when no customer is logged in. It has the contact details, `tags`, `orders_count`, `total_spent`, `orders`, `last_order`, `addresses`, `default_address` and `new_address`. See [customer](/themes/objects/customer). * `{% paginate customer.orders by 10 %}` paginates the orders, newest first. * A new `address` object describes customer and shipping addresses. See [address](/themes/objects/address). * `order` has `ref`, `name`, `created_at`, `financial_status`, `fulfillment_status`, `customer_url` and `shipping_address`. See [order](/themes/objects/order). * `routes` has `account_url`, `account_login_url`, `account_logout_url`, `account_register_url`, `account_recover_url` and `account_addresses_url`. See [routes](/themes/objects/routes). # Templates * New template types: `customer-login`, `customer-register`, `customer-account`, `customer-order`, `customer-addresses` and `customer-reset-password`. See [templates](/themes/templates/overview#template-types). * The templates are optional. Without one, the store shows its built-in page. * `customer-login` renders `/account/login` and `/account/recover`. `customer-account` renders `/account` and `/account/orders`. `customer-order` renders `/account/orders/{id}` with an `order` object. # Forms * New form types: `customer_login`, `create_customer`, `recover_customer_password`, `reset_customer_password`, `customer_update`, `customer`, `customer_address` and `customer_address_remove`. See [form](/themes/tags/form#customer-types). * The login, register, recover, reset and `customer` forms output a captcha. * `customer` subscribes an email to the store's marketing emails. # Storefront API * New endpoints: `POST /customers/logout`, `POST /customers/recover` and `POST /customers/reset`. See [customers](/store-front/customers/login). * `POST /customers/login` returns a bearer token that expires after 30 days. * `POST /customers` returns `202` when the email already belongs to a customer. The store then sends an email to finish the account. * `PUT /customers/account` needs `current_password` to change the email or the password. A new password returns a new token and revokes the others. * `GET /customers/orders` takes `page` and `limit`, and returns fewer fields for each order. * `POST /customers` and `PUT /customers/account` no longer take `country`, `region`, `city` or `notes`.