Shopify now lets an AI agent running in a shopper's browser complete a purchase on a Shopify store. A developer changelog entry dated 28 September 2026 added four WebMCP tools to Shopify checkout, so a browser agent can read the checkout, fill in delivery and payment details, and place the order "after buyer confirmation", with no merchant setup required. The catch sits in the same documentation: the tools skip several checkout types, the buyer still approves every order, and Shopify itself recommends a different, server-side route for most agents.
What Did Shopify Announce?
The changelog adds four tools that Shopify checkout registers in the buyer's browser tab:
| Tool | What it does, per Shopify's documentation |
|---|---|
get_checkout | Reads the current checkout state, or the order receipt on the Thank you page |
update_checkout | Replaces buyer contact, fulfilment, discount codes, declared fields and payment |
complete_checkout | Places the order after the buyer confirms it |
navigate_to_storefront | Leaves checkout and returns the tab to the storefront |
Shopify states that the tools "don't expose a new API or require merchant configuration" and are rolling out to all eligible merchants. They complete a set that began in August 2026, when Shopify added WebMCP tools to Liquid and Hydrogen storefronts for catalogue search, cart management, policy lookup and a hand-off to checkout. The storefront set is search_catalog, browse_store, get_product, show_variant, get_cart, update_cart, cancel_cart, proceed_to_checkout, manage_orders and search_shop_policies_and_faqs, and Shopify's WebMCP reference says it is provided on every Liquid storefront with nothing to install. With both releases live, a browser agent can move from product search to a placed order by calling declared tools rather than simulating clicks on the page.
What Can an Agent Change at Checkout?
The Checkout WebMCP guide lists the fields update_checkout can set:
- Buyer email and phone number
- Shipping address, or a saved Shop Pay address
- Delivery option, delivery instructions and pickup location
- Discount codes
- Declared fields, such as a tax number or store credit
- Payment: a saved Shop Pay card, Shop Pay approval, and billing address
The tool uses replace semantics, so an agent has to send the complete desired state each time, including values it wants to keep. Shopify notes that checkout clears most omitted values, so an agent that sends only the changed field can wipe the rest.
What Is WebMCP?
WebMCP is a proposed web standard that lets a website register structured tools, with names, descriptions and input schemas, that an AI agent in the browser can call directly instead of reading the screen and clicking through it. The specification is a draft report of the W3C Web Machine Learning Community Group, with editors from Microsoft and Google, and was first published in August 2025. Google's Chrome developer documentation describes it as a proposed standard currently available through an origin trial.
That status matters for merchants. Shopify's own WebMCP reference says agent support "is currently limited to Chromium-based browsers". A shopper using an agent inside Safari or Firefox gets none of this today, and a Community Group draft carries no guarantee of becoming a W3C standard.
How Does Checkout WebMCP Keep the Buyer in Control?
The headline says agents can check out. The documentation says agents can prepare a checkout and submit it once a human agrees, and it puts the job of asking on the agent itself. Shopify's Checkout WebMCP guide instructs developers: "Before you call complete_checkout, show the buyer the current order and total, and get their permission to place it."
Several steps stay with the buyer by design:
- Shop Pay login and payment challenges happen on the checkout page, and the agent waits for the status to change.
- 3D Secure authentication and blocking checkout UI extensions hand control back to the buyer, per the changelog.
- Review steps return a
requires_escalationstatus, and the buyer authorises on the page before the agent can try again.
Agents also have to identify themselves, and that work falls on the agent's developer, not the merchant. Shopify asks for browser requests to be signed with Web Bot Auth, using an Ed25519 key whose directory the developer registers with Shopify; the guide warns that without it, "bot detection might deprioritize or block your requests." It is the platform-side version of the agent identity problem that card networks are working on through their Know Your Agent framework.
Which Checkouts Does WebMCP Not Cover?
Shopify's carts and checkout documentation lists the checkouts where the tools are not registered, and tells agents to ask the buyer to finish on the page instead:
- Standard three-page checkout, unless the buyer checks out with Shop Pay
- B2B checkout
- Embedded checkout, and checkouts in mobile checkout SDKs
- Checkouts with merchandise from another shop
- Draft orders, order edits and payment collection
The first line is the one most merchants should check. On a store still running the three-page layout, a browser agent can only complete the order when the shopper pays with Shop Pay. Wholesale buyers on B2B checkout and shoppers inside mobile apps built on Shopify's checkout SDK are outside the release entirely. Checkout WebMCP also has no cancel tool, so an agent cannot abandon a checkout on the buyer's behalf.
Why Does Shopify Recommend Checkout MCP Instead?
The most telling line in the release is not in the changelog. In its carts and checkout guide, Shopify says it "recommends Checkout MCP" and to "Use Checkout WebMCP only when your agent is already operating in the buyer's browser."
The two routes share the same Universal Commerce Protocol (UCP) checkout object and statuses. They differ in where the agent lives:
| Checkout MCP (Shopify's recommended route) | Checkout WebMCP (new) | |
|---|---|---|
| Where the agent runs | Its own server | The buyer's browser tab |
| Depends on buyer's browser | No | Yes, Chromium-based only |
| Can create and cancel a checkout | Yes (create_checkout, cancel_checkout) | No; acts on the checkout the shopper already opened, reached from the storefront's proceed_to_checkout |
| Order placement | After the buyer completes payment on the storefront | After the buyer confirms in the tab |
| How the agent identifies itself | Authentication or a signed request | Web Bot Auth signature with a registered key |
The industry reading is that Shopify is covering both kinds of agent rather than betting on one. Assistants that run in the cloud, such as those inside chat apps, fit the server route. Agents built into browsers, which see the same page the shopper sees, fit WebMCP. A merchant on Shopify gets both without building either.
Is WebMCP Faster Than Browser Automation?
Shopify's team says so, with numbers that deserve a careful read. Gil Greenberg, who works on Shopify's agentic commerce team, published a test that Search Engine Journal reported on 29 September 2026. Both methods used the same model, prompts and starting conditions across ten checkout tasks on two test shops:
| Measure | WebMCP | Browser automation |
|---|---|---|
| Successful attempts | 60 of 60 | 56 of 60 |
| Time per attempt (excluding page setup) | 10.3 seconds | 27.4 seconds |
| Cost per attempt (at OpenAI's list prices) | 58% lower | Baseline |
On those figures, WebMCP was about 2.7 times faster per attempt. Three limits apply. The test ran on Shopify's own test shops with a single model. It excludes page setup time. And Search Engine Journal noted that one line of the original post gives a total that does not match the 60 attempts per method. The direction is plausible, since calling a declared tool removes the screen-reading step, but this is a vendor benchmark, not an independent one.
What Does This Mean for Agent Developers?
For teams building agents rather than running stores, the documentation sets out a fairly strict pattern. The first decision is architectural: an agent that can run on a server should use Checkout MCP, and Checkout WebMCP is for agents that already live in the browser. A browser agent then signs its requests with Web Bot Auth using a registered key, since Shopify verifies only registered keys and unverified traffic risks being deprioritised or blocked.
The flow itself is a loop rather than a single call. The agent reads the checkout, updates it, shows the buyer the order and total, and asks permission. If the checkout returns a hand-off, such as a Shop Pay login or a review step, the buyer acts on the page in the same tab, and Shopify's carts and checkout guide tells the agent to refresh its tool list and call get_checkout again afterwards. Only a completed status from complete_checkout means an order was placed.
What Should Shopify Merchants Do Now?
There is nothing to switch on: eligible stores already register the tools. The practical work is in the edges the tools expose.
- Check your checkout layout. If the store uses the three-page checkout, browser agents can only finish orders paid with Shop Pay.
- Audit checkout UI extensions. App-defined extension interactions are not covered by the tools, so any extension that blocks progress becomes a point where the agent stops and the buyer takes over.
- Keep structured data accurate. Agents call
search_catalogandget_productrather than reading pages, so catalogue errors reach the agent directly. - Watch agent orders separately. Shopper trust in agents paying remains low, with only 23% of US consumers trusting generative AI to handle payments in Visa's Trust Index, released on 9 September 2026 (analysed in the trust gap piece), so expect early volume to be small and worth measuring on its own.
Shopify has given browser agents a declared path through checkout instead of a page to guess at. Whether shoppers let them use it is a separate question that no changelog can answer.






