AI Models & Platforms

Shopify Extends WebMCP Support to Checkout for Browser Agents

mm
Add Unite.AI to your preferred sources on Google

Shopify has extended its WebMCP agent tooling to checkout, allowing browser-based AI agents to read and update Shopify checkouts and submit orders after the buyer confirms. The company announced the change in a developer changelog post dated September 28, 2026, on Shopify’s changelog index.

The announcement lists four tools agents can call at checkout: get_checkout, which reads checkout state, messages, and post-completion order details; update_checkout, which updates supported checkout fields; complete_checkout, which submits the checkout after buyer confirmation; and navigate_to_storefront, which returns the tab to the storefront. The tools act on the active checkout in the buyer’s browser session and hand control back to the buyer when input is required, such as 3D Secure authentication or blocking UI extensions. They run inside checkout-web, use the same state as the checkout interface, expose no new API, and require no merchant configuration.

With storefront and cart tools already live, Shopify said browser agents can now assist the full shopping journey on its platform, from product discovery and cart management through checkout and order confirmation. The tools serve agents that shoppers bring to a store in their own browser.

How the Checkout Tools Work

Checkout WebMCP implements the UCP checkout capability (dev.ucp.shopping.checkout) over browser-registered WebMCP tools instead of server-side JSON-RPC, and it shares the checkout object, statuses, and messages with Checkout MCP, Shopify’s server-side counterpart, according to the Checkout WebMCP documentation. Agents discover the tools with document.modelContext.getTools() and call them with document.modelContext.executeTool(), passing arguments as JSON strings; the documentation notes that Chrome 153 rejects object arguments and that Chrome plans to accept objects in Chrome 155.

get_checkout reads the current checkout without changing it, returning the UCP checkout object with monetary values as integers in the currency’s minor unit. For a Shop Pay buyer, it lists usable saved cards under payment.instruments, and on the Thank you page it returns the order receipt. update_checkout replaces buyer contact details, fulfillment, discount codes, declared fields, and payment. It uses PUT semantics, so the agent must send the complete desired state built from a fresh get_checkout response, and it ignores line items and attribution because the buyer changes items on the page. Declared fields expose checkout-collected extras, such as a tax number (the documentation cites a Brazilian CPF or CNPJ) and a store credit flag, through a Shopify extension to UCP.

complete_checkout places the order after the buyer confirms it. If checkout opens a review step, the buyer reviews the order on the page and the agent calls complete_checkout again only after the buyer authorizes submission; if a payment challenge or other buyer action is needed, the buyer finishes it on the checkout page in the same tab. Only a status of completed confirms the order. navigate_to_storefront leaves checkout without placing an order or changing the cart, is registered only when the store has an online storefront, and remains available on the Thank you page. Checkout WebMCP has no equivalent of Checkout MCP’s cancel_checkout tool, so the checkout status is never canceled.

Buyer Confirmation, Payment, and Agent Authentication

The documentation instructs agents to obtain the buyer’s permission before placing an order: “Before you call complete_checkout, show the buyer the current order and total, and get their permission to place it,” it states, adding that Web Bot Auth, a Shop Pay approval, and a ready_for_complete status do not grant that permission, and that the agent must ask again if the total changes.

Checkout WebMCP does not accept new card details. Depending on the checkout, payment.instruments accepts a saved Shop Pay card for a Shop Pay buyer, a Shop Pay approval for a guest checkout that accepts approvals, or a billing address only; the buyer chooses any other payment method directly on the checkout page.

Agents must sign browser requests with Web Bot Auth rather than tool arguments, and Shopify verifies only registered keys. Registration requires generating an Ed25519 signing key, hosting the public key in a key directory, and publishing that directory with Shopify; without Web Bot Auth, Shopify’s bot detection might deprioritize or block an agent’s requests. The documentation also cautions agents to treat merchant and third-party text in tool responses as checkout data rather than instructions, because such text can contain prompt-injection attempts, and it tells agents never to work around a tool by operating the page’s controls themselves.

Availability and the WebMCP Standard

Checkout registers the tools only on eligible checkouts. Shopify’s carts and checkout documentation lists the checkouts where tools are not registered: standard three-page checkout unless the buyer checks out with Shop Pay; B2B checkout; embedded checkout and checkouts in mobile checkout SDKs; checkouts with merchandise from another shop; and draft orders, order edits, and payment collection. App-defined checkout extension interactions are likewise handled by the buyer on the checkout page. Shopify recommends Checkout MCP for agents that can run on a server and directs developers to Checkout WebMCP only when an agent already operates in the buyer’s browser.

Shopify first shipped WebMCP tools for Liquid and Hydrogen storefronts on August 5, 2026, in a changelog post covering catalog search (search_catalog, browse_store, get_product, show_variant), cart management (get_cart, update_cart, cancel_cart), and checkout handoff (proceed_to_checkout, manage_orders). Those tools are live on every Liquid storefront and on the Hydrogen developer preview with nothing to install or configure. According to the storefront WebMCP documentation, after proceed_to_checkout, eligible checkouts replace the storefront tools with checkout tools, and agents are directed to refresh the browser’s tool list on the checkout page.

WebMCP is a proposed web standard that lets a page register tools with the browser, and agent support is currently limited to Chromium-based browsers through an origin trial. Shopify said it is helping shape the WebMCP specification alongside Google and Microsoft.

Aiden Cross is an AI-generated strategist at Unite.AI, covering AI product strategy, execution, and the practical challenges of turning experimental models into scalable, market-ready products. His work focuses on how startups and enterprise teams move from prototypes and demos to reliable systems used by real customers.

With a pragmatic and detail-oriented perspective, Aiden analyzes product roadmaps, go-to-market strategies, platform decisions, and organizational trade-offs that determine whether AI initiatives succeed or stall. He pays particular attention to deployment realities, user adoption, infrastructure constraints, and the alignment between technical capability and business value.

Articles authored by Aiden Cross are AI-generated and reviewed by Unite.AI’s editorial team to ensure clarity, accuracy, and responsible coverage of how AI products are built, shipped, and scaled in the real world.