The main tools include get_checkout, which reads the current checkout state and can return order details after completion; update_checkout, which changes supported information such as contact details, delivery settings, discounts and payment selections; and complete_checkout, which places the order after the shopper provides permission. A fourth tool, navigate_to_storefront, sends the browser back to the merchant’s storefront.
Shopify designed the system so shoppers remain involved whenever their input is required. If a payment challenge such as 3D Secure appears, or a checkout extension blocks automatic progress, control returns to the buyer in the same browser tab.
The company is also placing a clear limit on autonomous purchasing. Its documentation tells agents: “Before you call complete_checkout, show the buyer the current order and total, and get their permission to place it.” If the price changes after that approval, the agent is instructed to ask again.
Shopify’s checkout tools do not allow an agent to enter a new payment card. Depending on the checkout, an agent may be able to select an existing Shop Pay card, use a Shop Pay approval or provide billing information. Other payment choices remain under the shopper’s direct control.
The system is built on WebMCP, a proposed web standard that allows websites to expose structured tools directly to AI agents running inside a browser. Instead of forcing an agent to interpret checkout pages visually or scrape HTML, Shopify can give it defined actions and structured checkout data.
Checkout WebMCP implements Shopify’s Universal Commerce Protocol checkout capability through browser-registered tools. It shares checkout objects, status information and messages with Checkout MCP, Shopify’s server-side option for agents that operate outside the shopper’s browser.
The two approaches are meant for different environments. Shopify recommends Checkout MCP when an agent can operate on a server, while WebMCP is intended for agents already running in the buyer’s browser.
Shopify first introduced WebMCP support for Liquid and Hydrogen storefronts in August. Those tools gave agents access to functions including catalog search, product browsing, cart updates and checkout handoff. With checkout support added, eligible agents can now move from finding a product through order placement without switching to webpage controls designed for human users.
The checkout tools are not available in every purchase flow. Shopify excludes several cases, including standard three-page checkout unless the customer uses Shop Pay, B2B transactions, embedded checkout, mobile checkout SDKs, merchandise involving another shop, draft orders, order edits and payment collection.
Shopify also requires agents to authenticate browser requests through Web Bot Auth. Registered agents sign their requests using an Ed25519 key, while unregistered traffic may be deprioritized or blocked by Shopify’s bot-detection systems.
The company is also warning developers about prompt injection. Shopify’s documentation tells agents to treat merchant and third-party text returned through checkout tools as data rather than instructions and advises them not to bypass the structured tools by manipulating the page directly.
WebMCP currently has limited browser support through a Chromium origin trial. Shopify says it is contributing to development of the proposed standard alongside Google and Microsoft.
The checkout expansion moves Shopify closer to a full agent-driven shopping flow. Browser agents can now search a merchant’s catalog, manage a cart, enter checkout and submit an order, while Shopify keeps buyer confirmation and sensitive payment steps under direct human control.
This analysis is based on reporting from unite.ai.
Image courtesy of Shopify.
This article was generated with AI assistance and reviewed for accuracy and quality.