Shopify WebMCP checkout went live on September 28, 2026: an AI agent running in your browser can now read, fill in and submit a Shopify store’s checkout, including Shop Pay, instead of clicking through the page like a person (Shopify changelog). Shopify says the agent places the order only after you confirm it, and hands control back to you for steps such as 3D Secure card checks.

What changed

Shopify already gave browser agents WebMCP tools to search a store’s catalog and manage the cart. WebMCP is a proposed web standard: the page registers tools with the browser, and an agent calls them with structured inputs instead of reading the page’s code and simulating clicks (Shopify). The new release adds checkout tools (Shopify changelog):

  • get_checkout reads the checkout, its messages and, after purchase, the order details;
  • update_checkout changes supported fields such as contact details, delivery option, discount codes and payment;
  • complete_checkout submits the order after the buyer confirms;
  • navigate_to_storefront returns to the store.

The tools run inside Shopify’s checkout and use the same state as the checkout you see on screen. Shopify says they “don’t expose a new API or require merchant configuration” (Shopify changelog), so eligible stores get them without doing anything.

What it means for shoppers

  • You still approve the purchase. Shopify’s developer rules tell agents to show the buyer the current order and total and get permission before calling complete_checkout, and to ask again if the total changes. A Shop Pay approval on its own does not count as that permission (Shopify).
  • The agent can’t type in a new card. Checkout WebMCP does not accept new card details. It can pick one of your saved Shop Pay cards or use a Shop Pay approval; any other payment method you choose on the page yourself (Shopify).
  • Security checks stay with you. Shop Pay login, payment challenges and 3D Secure are completed by the buyer on the checkout page (Shopify).
  • The store is still the seller. Shopify says the merchant remains the merchant of record in agent checkouts (Shopify), so returns and refunds go through the store as usual. Our guide to who pays when an AI agent purchase goes wrong covers disputes.
  • Browser support is narrow for now. Shopify says agent support for WebMCP is limited to Chromium-based browsers (Shopify).

What it means for merchants

Nothing needs switching on, and Shopify’s changelog lists no merchant setting for the checkout tools (Shopify changelog). Orders placed this way go through your normal checkout, so your payment, fraud and refund settings still apply. This is separate from the Google AI Mode checkout that Shopify stores got by default last week, which runs inside Google’s own surfaces (Radlof). For how the protocols fit together, see our agentic payments explainer and the protocol tracker.