← Back to News
Innovation

Shopify opens its checkout to AI agents in shoppers’ browsers

AI agents in a shopper’s browser can now read, fill in, and submit eligible Shopify checkouts through WebMCP once the buyer confirms the order, with no new API or merchant setup. The tools take no new card details, and a 3-D Secure challenge hands control back to the buyer.

Shopify on September 28 let AI agents that run in a shopper’s browser read, fill in, and submit checkouts on eligible stores, through WebMCP tools registered on the checkout page itself. The release adds no new API and needs no setup from merchants. Shopify’s rules keep the buyer in charge: an agent must get the buyer’s permission before it places the order, the tools accept no new card details, and a 3-D Secure challenge goes back to the shopper on the page.

“Browser agents can now read and update Shopify checkouts using WebMCP tools for checkout,” Shopify said in a developer changelog post published at 10:30 a.m. ET (4:30 p.m. in Paris). Gil Greenberg, a staff product manager who works on agentic commerce at Shopify, wrote on X: “Today, we’re launching WebMCP support for checkout, including Shop Pay, for all eligible Shopify merchants.” TechCrunch reported the release the same day.

4
WebMCP tools registered on eligible checkouts
Shopify Developer changelog
60/60 vs. 56/60
successful checkout attempts, WebMCP vs. browser automation, in a Shopify test
Gil Greenberg (Shopify), post on X
10.3 s vs. 27.4 s
time per attempt in the same test, excluding page setup
Gil Greenberg (Shopify), post on X
58%
lower cost per attempt with WebMCP, at OpenAI’s list prices
Gil Greenberg (Shopify), post on X

Four tools that share the checkout page’s state

ToolWhat it does
get_checkoutReads the current checkout, or the order receipt on the Thank you page
update_checkoutReplaces buyer contact details, fulfillment, discount codes, declared fields, and payment
complete_checkoutPlaces the order after the buyer confirms it
navigate_to_storefrontLeaves checkout and returns the tab to the store, on shops that have an online storefront
WebMCP tools on Shopify checkout, as described in Shopify’s developer documentation.

The tools run inside checkout-web and “use the same state as the checkout UI,” according to the changelog. Each call acts on the checkout open in the shopper’s tab, runs through checkout’s own validation, and shows up on the page the buyer is looking at. update_checkout sends the complete desired state each time and ignores line items, which means an agent cannot change what is in the order at this stage. No tool cancels a checkout.

No new card details, and no order without the buyer’s go-ahead

“Checkout WebMCP doesn’t accept new card details,” Shopify’s reference states. For a Shop Pay buyer, an agent can select one of the saved cards that get_checkout lists. On a guest checkout, it can only set the billing address. The buyer chooses any other payment method on the checkout page.

🔑
3-D Secure hands control back to the buyer
“When the buyer’s input is required, such as 3D Secure authentication or for blocking UI extensions, the tools hand back control to the buyer,” the changelog says. The documentation sets out the sequence: the buyer completes the payment challenge on the checkout page, in the same tab, and the agent must not call complete_checkout again. It polls get_checkout instead, and only a completed status confirms the order.
Hands holding a smartphone that shows a passcode keypad, in front of an open laptop
Shop Pay login, payment challenges, and review steps remain with the shopper, on the checkout page.

Shopify’s reference spells out that consent step. Before calling complete_checkout, an agent must “show the buyer the current order and total, and get their permission to place it.” A Web Bot Auth signature or a ready_for_complete status “don’t grant it,” the reference says, and a changed total means asking again. The merchant always remains the merchant of record, according to Shopify’s documentation.

Eligible checkouts only, in Chromium browsers for now

Checkout registers the tools only on eligible checkouts. Shopify’s documentation lists the checkouts that get none, which the buyer completes on the page:

  • The standard three-page checkout, unless the buyer checks out with Shop Pay
  • B2B checkout
  • Embedded checkout, and checkouts in mobile checkout SDKs
  • Checkouts with merchandise from another shop
  • Draft orders, order edits, and payment collection

WebMCP itself is a proposed web standard that lets a page register tools with the browser, and agent support for it is currently limited to Chromium-based browsers, Shopify’s storefront documentation says. Agents must sign their browser requests with Web Bot Auth, or bot detection “might deprioritize or block” them. Shopify also warns agents to treat merchant and third-party text in tool responses as checkout data rather than instructions, because it “can contain prompt-injection attempts.”

The last step after storefront and cart tools

The release completes a sequence that began on August 5, when Shopify put WebMCP tools on every Liquid storefront and on the Hydrogen developer preview. Those tools let agents search the catalog, manage the cart, and take the shopper to checkout with proceed_to_checkout, without placing the order. On eligible checkouts, the storefront tools now give way to the checkout tools, and navigate_to_storefront leads back to the store.

Shopify still recommends a server-side route, Checkout MCP, in which an agent manages a checkout session from its own server. Both routes implement the checkout capability of the Universal Commerce Protocol (UCP), and Shopify’s guidance is to use Checkout WebMCP “only when your agent is already operating in the buyer’s browser.” AI agents Muse and Instinct already have direct agentic commerce partnerships with Shopify, TechCrunch noted, with the Instinct deal announced the same day.

Greenberg’s September 28 post links to an article on X with the results of a Shopify test pitting WebMCP against browser automation, in which an agent reads the page and clicks through it. Across 10 checkout tasks in two test shops, both methods ran on GPT-6 Sol “with the same prompts and starting conditions.” WebMCP succeeded in all 60 attempts, against 56 for browser automation. Search Engine Journal noted on September 29 that the results come from test shops and a single model, and that one total in Greenberg’s post does not match the 60 attempts listed per method.

Neither the changelog nor the documentation gives real-world data, such as orders placed by agents or conversion rates, SEJ points out. It also found that Shopify’s docs did not say, as of its September 29 article, whether merchants can switch off individual tools or separate agent-placed orders in their reports. Shopify’s developer changelog carried no further update on the checkout tools through October 1.

Provenance

Published September 28, 2026

8 sources, 4 distinct domains

↗ Shopify Developer changelog, WebMCP support for checkout · shopify.dev↗ Shopify.dev, Checkout WebMCP reference · shopify.dev↗ Shopify.dev, About carts and checkout · shopify.dev↗ Shopify.dev, WebMCP storefront tools · shopify.dev↗ Shopify Developer changelog, WebMCP support for Liquid and Hydrogen storefronts · shopify.dev↗ Gil Greenberg (Shopify), post on X, September 28, 2026 · x.com↗ TechCrunch, Shopify opens checkout to browser-based AI agents · techcrunch.com↗ Search Engine Journal, Shopify Extends WebMCP Into Checkout For Browser Agents · searchenginejournal.com
← All news